CVE-2016-0793 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 15.6% (pctl 97)
Patch early
A public exploit exists.
Description
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 15.57% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-04-01 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows |
| redhat | jboss wildfly application server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass | 2016-03-20 |
References
- http://packetstormsecurity.com/files/136323/Wildfly-Filter-Restriction-Bypass-Information-Disclosure.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1305937
- https://security.netapp.com/advisory/ntap-20180215-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03784en_us
- https://www.exploit-db.com/exploits/39573/
- http://packetstormsecurity.com/files/136323/Wildfly-Filter-Restriction-Bypass-Information-Disclosure.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1305937
- https://security.netapp.com/advisory/ntap-20180215-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03784en_us
- https://www.exploit-db.com/exploits/39573/
→ the Explorer · watch your stack · NVD