peter bassill · operator
$ cve CVE-2016-0793 JSON

CVE-2016-0793 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS15.57% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2016-04-01
Last modified2026-06-17

Affected (2)

VendorProduct
microsoftwindows
redhatjboss wildfly application server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD