CVE Vulnerabilities

CVE-2006-5750

Published: Nov 27, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the console manager.

Affected Software

Name Vendor Start Version End Version
Jboss_application_server Jboss 3.2.5_final (including) 3.2.5_final (including)
Jboss_application_server Jboss 3.2.6_final (including) 3.2.6_final (including)
Jboss_application_server Jboss 3.2.7_final (including) 3.2.7_final (including)
Jboss_application_server Jboss 3.2.8.sp1 (including) 3.2.8.sp1 (including)
Jboss_application_server Jboss 3.2.8_final (including) 3.2.8_final (including)
Jboss_application_server Jboss 4.0.0_final (including) 4.0.0_final (including)
Jboss_application_server Jboss 4.0.1_final (including) 4.0.1_final (including)
Jboss_application_server Jboss 4.0.1_sp1 (including) 4.0.1_sp1 (including)
Jboss_application_server Jboss 4.0.2_final (including) 4.0.2_final (including)
Jboss_application_server Jboss 4.0.3_final (including) 4.0.3_final (including)
Jboss_application_server Jboss 4.0.4.ga (including) 4.0.4.ga (including)
Jboss_application_server Jboss 4.0.5.ga (including) 4.0.5.ga (including)
Red Hat Web Application Stack for RHEL 4 RedHat jbossas-0:4.0.4-1.el4s1.25 *

References