VulnerabilityModified
CVE-2009-0278
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.
MEDIUM 5.0EPSS 2.24%
Does this matter?
Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.
Description
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sun/java system application server
- Source
- cve@mitre.org
References
- http://osvdb.org/51604
- http://secunia.com/advisories/33725
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-245446-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/33397
- http://www.vupen.com/english/advisories/2009/0208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48161
- http://osvdb.org/51604
- http://secunia.com/advisories/33725
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-245446-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/33397
- http://www.vupen.com/english/advisories/2009/0208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48161
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.