CVE-2017-2595
published 2018-07-27CVE-2017-2595: It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
PriorityP338medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
3.10%
86.4th percentile
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wildfly: Arbitrary file read via path traversal
vendor_redhat·2017-06-07·CVSS 7.7
CVE-2017-2595 [HIGH] CWE-22 wildfly: Arbitrary file read via path traversal
wildfly: Arbitrary file read via path traversal
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Package: wildfly (Red Hat Single Sign-On 7) - Under investigation
GHSA
GHSA-94q8-x74c-h24h: It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traver
ghsa_unreviewed·2022-05-13
CVE-2017-2595 [MEDIUM] CWE-22 GHSA-94q8-x74c-h24h: It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traver
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://rhn.redhat.com/errata/RHSA-2017-1551.htmlhttp://www.securityfocus.com/bid/98967http://www.securitytracker.com/id/1038757https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:1548https://access.redhat.com/errata/RHSA-2017:1549https://access.redhat.com/errata/RHSA-2017:1550https://access.redhat.com/errata/RHSA-2017:1552https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2595http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://rhn.redhat.com/errata/RHSA-2017-1551.htmlhttp://www.securityfocus.com/bid/98967http://www.securitytracker.com/id/1038757https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:1548https://access.redhat.com/errata/RHSA-2017:1549https://access.redhat.com/errata/RHSA-2017:1550https://access.redhat.com/errata/RHSA-2017:1552https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2595
2018-07-27
Published