Was able to find: https://issues.jboss.org/browse/JBPAPP-2274 how do I go ahead and apply this patch?
Since you're using JBoss AS 5.1.0.GA, it's probably better to use the corresponding patch from here: https://issues.jboss.org/browse/JBAS-7105
This patch can be applied as follows from the jboss-5.1.0.GA-src directory:
patch -p0 < /path/to/JBAS-7105.patch
Tried going to your link and getting:
It seems that you have tried to perform an operation which you are not permitted to perform.
If you think this message is wrong, please contact your JIRA administrators.
went to: https://issues.jboss.org/browse/JBPAPP-2274 as per CVE-2009-2405
Sorry about that. I just checked and the two patches are actually identical.
JBPAPP-2274.patch can be applied as described above, i.e., patch -p0 < /path/to/patch/file
So do I apply this to the source files of JBoss, I usually get the zip containing the binary files from: http://sourceforge.net/projects/jboss/files/JBoss/JBoss-5.1.0.GA via http://www.jboss.org/jbossas/downloads
Sorry again, still a little bit lost, after opening the .patch file do see: varia/src/resources/jmx/html/displayMBeans.jsp which makes reference to a file that does exists in my JBoss /server/default configuration but also see the reference to src... Source
So would this patch be targeting the source files to later be compiled or just the regular folder that I have?
Thanks again for your help.
So the patch works well with the web-console.war files, but doesn't want to play with the JMX portion:
Edited the file and removed the web-console piece and left the JMX one, reverted the files from the previously made backup and still spitting the same on this section.
patch -p0 < JBPAPP-2274-JMX.patch
patching file varia/src/resources/jmx/html/inspectMBean.jsp
Hunk #1 succeeded at 166 with fuzz 2 (offset 144 lines).
Hunk #2 FAILED at 228.
Hunk #3 FAILED at 317.
2 out of 3 hunks FAILED -- saving rejects to file varia/src/resources/jmx/html/inspectMBean.jsp.rej
patching file varia/src/resources/jmx/html/displayMBeans.jsp
Hunk #1 succeeded at 25 with fuzz 2 (offset 24 lines).
Hunk #2 FAILED at 92.
1 out of 2 hunks FAILED -- saving rejects to file varia/src/resources/jmx/html/displayMBeans.jsp.rej
Waiting to hear back if it addressed the web-console issues which were the ones raised up.
Will update the thread