First published: Mon Apr 26 2010(Updated: )
The JBoss Enterprise Application Platform 4.2.0.CP03 and 4.3.0.CP01 updates for Red Hat Enterprise Linux 4 and 5 fixed an issue (<a href="https://access.redhat.com/security/cve/CVE-2008-3273">CVE-2008-3273</a>) where unauthenticated users were able to access the status servlet; however, a bug fix included in the 4.2.0.CP06 and 4.3.0.CP04 updates re-introduced the issue. A remote attacker could use this flaw to acquire details about deployed web contexts.
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-585900 is considered moderate due to its potential impact on unauthorized access.
To fix REDHAT-BUG-585900, you should update the JBoss Enterprise Application Platform to the latest patched version provided by Red Hat.
REDHAT-BUG-585900 addresses a bug fix for CVE-2008-3273 related to unauthenticated access to the status servlet.
The affected products for REDHAT-BUG-585900 include JBoss Enterprise Application Platform versions 4.2.0.CP03 and 4.3.0.CP01.
REDHAT-BUG-585900 was reported as part of ongoing security improvements to align with vulnerabilities fixed in earlier releases.