CVE-2008-3273
Last modified
CVE-2008-3273 is a vulnerability of currently unknown severity. JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.. EPSS estimates a 47.11% chance of exploitation in the next 30 days.
Description
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jboss | Enterprise Application Platform | <= 4.2.0.cp03 |
| Jboss | Enterprise Application Platform | <= 4.3.0 |
| Jboss | Enterprise Application Platform | 4.2.0.cp01 |
| Jboss | Enterprise Application Platform | 4.2.0.cp02 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3273?
How severe is CVE-2008-3273?
How do I fix CVE-2008-3273?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3267SQL injection vulnerability in mojoJobs.cgi in MojoJobs allo…
- CVE-2008-3268Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2…
- CVE-2008-3269WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 …
- CVE-2008-3270yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not…
- CVE-2008-3271Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote a…
- CVE-2008-3272The snd_seq_oss_synth_make_info function in sound/core/seq/o…
- CVE-2008-3274The default configuration of Red Hat Enterprise IPA 1.0.0 an…
- CVE-2008-3275The (1) real_lookup and (2) __lookup_hash functions in fs/na…5.5
- CVE-2008-3276Integer overflow in the dccp_setsockopt_change function in n…
- CVE-2008-3277Untrusted search path vulnerability in a certain Red Hat bui…
- CVE-2008-3278frysk packages through 2008-08-05 as shipped in Red Hat Ente…7.8
- CVE-2008-3279Untrusted search path vulnerability in libbrlttybba.so in br…
Are you affected by CVE-2008-3273?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
