// For flags

CVE-2008-3273

JBossEAP status servlet info leak

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

JBoss Enterprise Application Platform (también conocido como JBossEAP o EAP) anterior a 4.2.0.CP03 y 4.3.0 anterior a 4.3.0.CP01, permite a atacantes remotos obtener información sensible relacionada con "deployed web contexts" (Contextos web desarrollados) a través de una petición al servlet de estado, como se ha demostrado mediante la cadena de consulta full=true.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-07-24 CVE Reserved
  • 2008-08-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-01 First Exploit
  • 2025-06-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Jboss
Search vendor "Jboss"
Enterprise Application Platform
Search vendor "Jboss" for product "Enterprise Application Platform"
<= 4.2.0.cp03
Search vendor "Jboss" for product "Enterprise Application Platform" and version " <= 4.2.0.cp03"
-
Affected
Jboss
Search vendor "Jboss"
Enterprise Application Platform
Search vendor "Jboss" for product "Enterprise Application Platform"
<= 4.3.0
Search vendor "Jboss" for product "Enterprise Application Platform" and version " <= 4.3.0"
-
Affected
Jboss
Search vendor "Jboss"
Enterprise Application Platform
Search vendor "Jboss" for product "Enterprise Application Platform"
4.2.0.cp01
Search vendor "Jboss" for product "Enterprise Application Platform" and version "4.2.0.cp01"
-
Affected
Jboss
Search vendor "Jboss"
Enterprise Application Platform
Search vendor "Jboss" for product "Enterprise Application Platform"
4.2.0.cp02
Search vendor "Jboss" for product "Enterprise Application Platform" and version "4.2.0.cp02"
-
Affected