Uploaded image for project: 'JBoss Web Services'
  1. JBoss Web Services
  2. JBWS-1514

Soap Messages should not have system properties relaced

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • jbossws-1.2.0
    • jbossws-1.0.4
    • None
    • None
    • Low

    Description

      At the moment if a Soap message contains a string in the format ${property} the property is replaced with a system property, this means in theory it would be possible for a client to get access to any system properties - especially if any fault or response messages contain fields from the incomming request.

      Attachments

        Activity

          People

            tdiesler@redhat.com Thomas Diesler
            darran.lofthouse@redhat.com Darran Lofthouse
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: