-
Bug
-
Resolution: Done
-
Critical
-
4.2.0.GA_CP05
-
None
-
None
-
Release Notes
The issue is that using in any wsdl access url if you suffix &resource=../../../jmx-invoker-service.xml you can view this file. Likewise in a system where JBossEAP is running you can easily hack to view any xml file from any arbitrary location using this method.
- blocks
-
JBPAPP-734 Upgrade JBossWS to 1.2.1.GA_CP04
- Resolved