4.2.2 is using JBossWEB 2.0.1.GA and the vulnerabilities are not fixed in old community
versions.
If you want to be safe use Jboss supported product.
You can also build JWB 2.0.x from the lastest CP tag and replace the jar files in you
4.2.2. (Look in the forum it is already explain somewhere).
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4193929#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...