JBoss Application Server DeploymentFileRepository Directory Traversal Vulnerability affected version: jbossApplicationServer4.0.4 program Introduction: Jboss is a very popular open-source J2EE application server. Vulnerability Analysis: The DeploymentFileRepository class of the JBoss application server does not properly filter user input. The authenticated remote
JBoss Application Server DeploymentFileRepository Directory Traversal Vulnerability
Affected Versions:
Jboss AppliCatIon Server 4.0.4
Program introduction:
Jboss is a very popular open-source J2EE application server.
Vulnerability Analysis:
The DeploymentFileRepository class of the JBoss application server does not properly filter user input. authenticated remote users can submit malicious requests to the console manager listening to port 8080 by default for directory traversal attacks, attackers can read, delete, overwrite, or modify arbitrary files, and finally execute arbitraryCommand.
Vulnerability exploitation:
Http://www.metasploit.com or rEdMine/projects/framework/repository/enTrY/moDuLes/ExPloits/multi/http/jb
Solution:
Vendor patch:
RedHat
------
For this reason, RedHat has released a Security Bulletin (RHSA-2006: 0743-01) and patch:
RHSA-2006: 0743-01: Critical: jbossas security upDate