REDHAT-BUG-2259475: Medium severity Red Hat JBoss EAP vulnerability
A potential directory traversal vulnerability in JBoss EAP was discovered. Initial tests determined that appending "/..;/" to a request will return the JBoss EAP welcome page from the / directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2259475?
REDHAT-BUG-2259475 has been classified as a potential directory traversal vulnerability.
How do I fix REDHAT-BUG-2259475?
To mitigate REDHAT-BUG-2259475, ensure that your JBoss EAP is updated to the latest version that addresses this vulnerability.
What versions of JBoss EAP are affected by REDHAT-BUG-2259475?
All versions of Red Hat JBoss EAP that are susceptible to directory traversal issues may be affected by REDHAT-BUG-2259475.
What happens if REDHAT-BUG-2259475 is exploited?
Exploiting REDHAT-BUG-2259475 could allow an attacker to access the JBoss EAP welcome page, potentially revealing sensitive information.
How can I verify if my JBoss EAP installation is vulnerable to REDHAT-BUG-2259475?
You can check for the vulnerability by testing for the directory traversal issue using the specific request format outlined in the vulnerability description.