CVE-2015-3198: Red Hat JBoss Wildfly Application Server
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.
Affected products
- Red Hat JBoss Wildfly Application Server: version 9.0.0 only
Published 2017-07-21. Last modified 2026-06-17.