Directory Traversal Affecting eap7-jcl-over-slf4j package, versions <0:1.7.22-2.redhat_1.1.ep7.el7
Threat Intelligence
EPSS
0.21% (60th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-EAP7JCLOVERSLF4J-5330566
- published 26 Mar 2023
- disclosed 7 Jun 2017
How to fix?
Upgrade RHEL:7
eap7-jcl-over-slf4j
to version 0:1.7.22-2.redhat_1.1.ep7.el7 or higher.
This issue was patched in RHSA-2017:3455
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream eap7-jcl-over-slf4j
package and not the eap7-jcl-over-slf4j
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
References
- https://access.redhat.com/security/cve/CVE-2017-2595
- http://rhn.redhat.com/errata/RHSA-2017-1409.html
- http://rhn.redhat.com/errata/RHSA-2017-1551.html
- http://www.securityfocus.com/bid/98967
- http://www.securitytracker.com/id/1038757
- https://access.redhat.com/errata/RHSA-2017:3455
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2595