CVE-2009-0027

Publication date 9 March 2009

Last updated 24 July 2024


Ubuntu priority

Description

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

Status

Package Ubuntu Release Status
jbossas4 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities