Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
BID:65051
Info
Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
| Bugtraq ID: | 65051 |
| Class: | Design Error |
| CVE: |
CVE-2013-6447 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2013 12:00AM |
| Updated: | Dec 18 2013 12:00AM |
| Credit: | Jon Passki, Coverity SRL. |
| Vulnerable: |
Redhat JBoss Web Framework Kit 2.4 |
| Not Vulnerable: | |
Discussion
Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
Red Hat JBoss Web Framework Kit is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid to perform future attacks.
Red Hat JBoss Web Framework Kit is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid to perform future attacks.
Exploit / POC
Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat JBoss Web Framework Kit Information Disclosure Vulnerability
References:
References:
- Red Hat JBoss Web Framework Kit Homepage (Red Hat)
- JBoss Seam: Information disclosure in remoting (Red Hat Bugzilla)
- Security Advisory Moderate: Red Hat JBoss Web Framework Kit 2.4.0 update (Red Hat)