← Vulnerability feed

Vulnerability record · CVE-2016-0793 · published 1 April 2016

CVE-2016-0793: Redhat jboss wildfly application server information exposure vulnerability

Redhat · Jboss Wildfly Application Server

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.

7.5 CVSS 3.0 High EPSS 16% · top 3.3% CWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 5.0
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2016-9589Redhat jboss wildfly application server uncontrolled resource consumption vulnerabilityUndertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cac…EPSS 3.0%7.5CVE-2015-3198Redhat jboss wildfly application server information exposure vulnerabilityThe Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…EPSS 1.8%6.8CVE-2015-5188Redhat jboss enterprise application platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …EPSS 1.1%6.1CVE-2016-4993Redhat jboss enterprise application platform vulnerabilityCRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before …EPSS 2.6%5.5CVE-2018-1047Redhat jboss wildfly application server improper input validation vulnerabilityA flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…EPSS 0.51%5.0CVE-2015-5220Redhat jboss enterprise application platform memory buffer overflow vulnerabilityThe Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers…EPSS 3.0%4.3CVE-2015-5178Redhat jboss wildfly application server vulnerabilityThe Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Fra…EPSS 1.7%1.9CVE-2014-0018Redhat jboss enterprise application platform permissions and access controls vulnerabilityRed Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2016-0793), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.