Back

HIGH

wildfly: WEB-INF and META-INF Information Disclosure via Filter Restriction Bypass

Published Apr 1, 2016

Description

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.

Affected products

Remediation

Red Hat statement

Only Wildfly application servers running on Windows operating systems are affected; no versions of Red Hat JBoss EAP or layered products are affected.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 1, 2016
Updated Aug 5, 2024
Reserved Dec 16, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2016
GHSA-9Q87-22GR-R8QF