Red Hat Bugzilla – Bug 479668
CVE-2009-0027 JBoss EAP unprivileged local xml file access
Last modified: 2013-07-29 04:01:23 EDT
The request handler in JBossWS does not correctly verify the resource path when serving WSDL files for custom web service endpoints. This allows remote attackers to read arbitrary XML files with the permissions of the EAP process.