Illegalaccess.org has discovered a critical security vulnerability in the latest production version of JBoss J2EE application server.
Tutorial Details:
The vulnerability affects default installations of JBoss 3.0.8/3.2.1 running on JDK 1.4.x. We were able to design proof of concept code for this issue, which allows remote attack resulting in several compromises, ranging from information disclosure over log manipulation and manipulating java process properties to execution of any commands on the (windows) system with the privileges of the JBoss process. We do not rule out the possibility of remotely controlled code execution on JBoss servers running on top of other operating systems
Read
Tutorial at: Click here to view the tutorial
Rate Tutorial: www.illegalaccess.org - JVM vulnerabilities
View Tutorial: www.illegalaccess.org - JVM vulnerabilities
Related
Tutorials:
|