CVE-2009-0278

Sun Java System AS <8.2 - Info Disclosure

Title source: llm

Description

Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.

Scores

EPSS 0.0047
EPSS Percentile 64.1%

Classification

CWE
CWE-200
Status draft

Affected Products (8)

sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server
sun/java_system_application_server

Timeline

Published Jan 27, 2009
Tracked Since Feb 18, 2026