Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2018-1047

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 2.1
  • AV:L/AC:L/Au:N/C:P/I:N/A:N
Software From Fixed in
redhat / jboss_wildfly_application_server 9.0.0-beta1 9.0.0-beta1.x
redhat / jboss_wildfly_application_server 9.0.0-beta2 9.0.0-beta2.x
redhat / jboss_wildfly_application_server 10.0.0 10.0.0.x
redhat / jboss_wildfly_application_server 9.0.0-cr1 9.0.0-cr1.x
redhat / jboss_wildfly_application_server 9.0.0 9.0.0.x
redhat / jboss_wildfly_application_server 9.0.0-alpha1 9.0.0-alpha1.x
redhat / jboss_wildfly_application_server 9.0.0-cr2 9.0.0-cr2.x
redhat / jboss_wildfly_application_server 9.0.1 9.0.1.x
redhat / jboss_wildfly_application_server 9.0.2 9.0.2.x
redhat / jboss_wildfly_application_server 10.0.0-alpha1 10.0.0-alpha1.x
redhat / jboss_wildfly_application_server 10.0.0-alpha2 10.0.0-alpha2.x
redhat / jboss_wildfly_application_server 10.0.0-alpha3 10.0.0-alpha3.x
redhat / jboss_wildfly_application_server 10.0.0-alpha4 10.0.0-alpha4.x
redhat / jboss_wildfly_application_server 10.0.0-alpha5 10.0.0-alpha5.x
redhat / jboss_wildfly_application_server 10.0.0-alpha6 10.0.0-alpha6.x
redhat / jboss_wildfly_application_server 10.0.0-beta1 10.0.0-beta1.x
redhat / jboss_wildfly_application_server 10.0.0-beta2 10.0.0-beta2.x
redhat / jboss_wildfly_application_server 10.0.0-cr1 10.0.0-cr1.x
redhat / jboss_wildfly_application_server 10.0.0-cr2 10.0.0-cr2.x
redhat / jboss_wildfly_application_server 10.0.0-cr3 10.0.0-cr3.x
redhat / jboss_wildfly_application_server 10.0.0-cr4 10.0.0-cr4.x
redhat / jboss_wildfly_application_server 10.0.0-cr5 10.0.0-cr5.x
redhat / jboss_wildfly_application_server 10.1.0 10.1.0.x
redhat / jboss_wildfly_application_server 10.1.0-cr1 10.1.0-cr1.x
redhat / jboss_wildfly_application_server 11.0.0 11.0.0.x
redhat / jboss_wildfly_application_server 11.0.0-alpha1 11.0.0-alpha1.x
redhat / jboss_wildfly_application_server 11.0.0-beta1 11.0.0-beta1.x
redhat / jboss_wildfly_application_server 11.0.0-cr1 11.0.0-cr1.x
redhat / jboss_enterprise_application_platform 7.1.0 7.1.0.x
org.wildfly / wildfly-undertow - 12.0.0