Description
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Remediation
References
Related Vulnerabilities
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)
Oracle Database Server CVE-2018-2939 Vulnerability (CVE-2018-2939)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5715)
WordPress 4.2.x Same Origin Method Execution (SOME) Vulnerability (4.2 - 4.2.7)