VDB

CVE-2008-3273

CVE-2008-3273 PUBLISHED CVSS 5 MEDIUM

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

EPSS 41.40% · 97.5th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
41.40%
97.5th percentile

Affected Products

VendorProductVersions
n/an/a*
jbossenterprise_application_platform4.2.0.cp02, 0, 0

Timeline

  • CVE Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Aug 30, 2024 PoC Published
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Mar 17, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›