Uploaded image for project: 'JBoss Web Services'
  1. JBoss Web Services
  2. JBWS-1514

Soap Messages should not have system properties relaced

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • jbossws-1.2.0
    • jbossws-1.0.4
    • None
    • None
    • Low

      At the moment if a Soap message contains a string in the format ${property} the property is replaced with a system property, this means in theory it would be possible for a client to get access to any system properties - especially if any fault or response messages contain fields from the incomming request.

              tdiesler@redhat.com Thomas Diesler
              darran.lofthouse@redhat.com Darran Lofthouse
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: