You can also check out
http://anonsvn.jboss.org/repos/jbossweb/branches/JBOSSWEB_2_0_0_GA_CP/ and build JBossWEB
then you need to copy the jbossweb jar files to replace your 4.2.2 version.
If you don't have URIEncoding="UTF-8" in the connector entries of server.xml
you aren't at risk with CVE-2008-2938.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4172590#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...