CVE-2015-3198: Red Hat JBoss Wildfly Application Server

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.

Affected products

  • Red Hat JBoss Wildfly Application Server: version 9.0.0 only

Published 2017-07-21. Last modified 2026-06-17.