CVE-2009-0278Sensitive Information Exposure in Java System Application Server

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateMay 2

Description

Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hx8m-v8g6-c563: Sun Java System Application Server (AS) 82022-05-02
CVEList
CVE-2009-0278: Sun Java System Application Server (AS) 82009-01-27

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows Live Messenger 2009 - ActiveX Denial of Service2010-01-08
CVE-2009-0278 — Sensitive Information Exposure | cvebase