Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23990
HistoryApr 10, 2020 - 12:42 a.m.

Information Disclosure

2020-04-1000:42:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.088 Low

EPSS

Percentile

94.6%

jboss AS web console is vulnerable to information disclosure. Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. This release contains a Web Console with an updated configuration that now blocks all unauthenticated access to it by default.