-
Bug
-
Resolution: Done
-
Blocker
-
4.3.0.GA_CP03
-
None
-
Release Notes
The issue is that using in any wsdl access url if you suffix &resource=../../../jmx-invoker-service.xml you can view this file. Likewise in a system where JBossEAP is running you can easily hack to view any xml file from any arbitrary location using this method.
- blocks
-
JBPAPP-1210 Release and upgrade to JBossWS 2.0.1.SP2_CP05
- Resolved