CVE-2012-1094

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.18 % (55th)
0.18% Progress
Affected Products 1
Advisories 1

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2020-03-10 17:15:12
(4 years ago)
Updated Date
2020-03-10 20:57:31
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Jboss Application Server from 7.0.0 version and prior 7.1.1 version cpe:2.3:a:redhat:jboss_application_server >= 7.0.0 < 7.1.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...