LWN.net Logo

jbossas: arbitrary code execution

Package(s):jbossas CVE #(s):CVE-2006-5750
Created:November 27, 2006 Updated:November 29, 2006
Description: Symantec discovered a flaw in the DeploymentFileRepository class of the JBoss Application Server. A remote attacker who is able to access the console manager could read or write to files with the permissions of the JBoss user. This could potentially lead to arbitrary code execution as the jboss user.
Alerts:
Red Hat RHSA-2006:0743-01 2006-11-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds