First published: Mon Jan 22 2024(Updated: )
A potential directory traversal vulnerability in JBoss EAP was discovered. Initial tests determined that appending "/..;/" to a request will return the JBoss EAP welcome page from the / directory.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise Application Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2259475 has been classified as a potential directory traversal vulnerability.
To mitigate REDHAT-BUG-2259475, ensure that your JBoss EAP is updated to the latest version that addresses this vulnerability.
All versions of Red Hat JBoss EAP that are susceptible to directory traversal issues may be affected by REDHAT-BUG-2259475.
Exploiting REDHAT-BUG-2259475 could allow an attacker to access the JBoss EAP welcome page, potentially revealing sensitive information.
You can check for the vulnerability by testing for the directory traversal issue using the specific request format outlined in the vulnerability description.