CVE Vulnerabilities

CVE-2006-5750

Published: Nov 27, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the console manager.

Affected Software

NameVendorStart VersionEnd Version
Jboss_application_serverJboss3.2.5_final (including)3.2.5_final (including)
Jboss_application_serverJboss3.2.6_final (including)3.2.6_final (including)
Jboss_application_serverJboss3.2.7_final (including)3.2.7_final (including)
Jboss_application_serverJboss3.2.8.sp1 (including)3.2.8.sp1 (including)
Jboss_application_serverJboss3.2.8_final (including)3.2.8_final (including)
Jboss_application_serverJboss4.0.0_final (including)4.0.0_final (including)
Jboss_application_serverJboss4.0.1_final (including)4.0.1_final (including)
Jboss_application_serverJboss4.0.1_sp1 (including)4.0.1_sp1 (including)
Jboss_application_serverJboss4.0.2_final (including)4.0.2_final (including)
Jboss_application_serverJboss4.0.3_final (including)4.0.3_final (including)
Jboss_application_serverJboss4.0.4.ga (including)4.0.4.ga (including)
Jboss_application_serverJboss4.0.5.ga (including)4.0.5.ga (including)
Red Hat Web Application Stack for RHEL 4RedHatjbossas-0:4.0.4-1.el4s1.25*

References