REDHAT-BUG-1044794: Low severity jboss seam remoting vulnerability
It was found that the InterfaceGenerator handler in JBoss Seam Remoting will expose details of all classes and methods on the server's classpath, not just methods with the org.jboss.seam.annotations.remoting.WebRemote annotation. A remote attacker could use this flaw to determine which classes are deployed on the JBoss server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1044794?
The severity of REDHAT-BUG-1044794 is classified as high due to the potential information disclosure risk.
How can I mitigate REDHAT-BUG-1044794?
To mitigate REDHAT-BUG-1044794, restrict access to the JBoss Seam Remoting service and apply any available patches.
What impact does REDHAT-BUG-1044794 have on affected systems?
REDHAT-BUG-1044794 may allow remote attackers to expose sensitive class and method details from the server's classpath.
Is there a patch available for REDHAT-BUG-1044794?
Yes, a patch is available for REDHAT-BUG-1044794 and should be applied to affected systems.
What software versions are affected by REDHAT-BUG-1044794?
JBoss Seam Remoting is affected by REDHAT-BUG-1044794, particularly versions that do not have the latest security updates applied.