{"id":13636026,"url":"https://github.com/ilmila/J2EEScan","last_synced_at":"2025-04-19T04:31:50.170Z","repository":{"id":29688623,"uuid":"33231213","full_name":"ilmila/J2EEScan","owner":"ilmila","description":"J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.","archived":false,"fork":false,"pushed_at":"2023-11-14T07:54:33.000Z","size":421,"stargazers_count":652,"open_issues_count":17,"forks_count":185,"subscribers_count":36,"default_branch":"master","last_synced_at":"2025-04-02T06:35:59.554Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ilmila.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2015-04-01T06:43:44.000Z","updated_at":"2025-03-30T19:37:58.000Z","dependencies_parsed_at":"2023-01-14T15:27:43.880Z","dependency_job_id":"f60ed410-2842-429f-b70d-b66996299b6c","html_url":"https://github.com/ilmila/J2EEScan","commit_stats":null,"previous_names":[],"tags_count":4,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilmila%2FJ2EEScan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilmila%2FJ2EEScan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilmila%2FJ2EEScan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilmila%2FJ2EEScan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ilmila","download_url":"https://codeload.github.com/ilmila/J2EEScan/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249606378,"owners_count":21298851,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T00:00:55.631Z","updated_at":"2025-04-19T04:31:49.869Z","avatar_url":"https://github.com/ilmila.png","language":"Java","funding_links":[],"categories":["Scanners","Java","Java (504)"],"sub_categories":[],"readme":"# J2EEScan - J2EE Security Scanner Burp Suite Plugin\n\n[![Join the chat at https://gitter.im/ilmila/J2EEScan](https://badges.gitter.im/ilmila/J2EEScan.svg)](https://gitter.im/ilmila/J2EEScan?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge) [![Donate](https://img.shields.io/badge/Donate-PayPal-green.svg)](https://PayPal.Me/ilmila)\n\n\n\n## What is J2EEScan\nJ2EEScan is a plugin for [Burp Suite Proxy](http://portswigger.net/). \nThe goal of this plugin is to improve the test coverage during \nweb application penetration tests on J2EE applications. \n\n\n## How does it works?\n\nThe plugin is fully integrated into the Burp Suite Scanner; it adds **more than 80+ unique security test \ncases** and new strategies to discover different kind of J2EE vulnerabilities.\n\n\n ![IMAGE](assets/issues-example.png)\n\n\n## How to install ?\n\n * From \"Cookie jar\" section in \"Options\" -\u003e \"Sessions\" enable the Scanner and Extender fields\n * Load the J2EEscan jar in the Burp Extender tab\n * The plugin requires at least Java 1.7\n\n\n## Contributors:\n\nSpecial thanks to\n\n  * [@h3xstream](https://twitter.com/h3xstream)\n  * [@martinbydefault](https://github.com/martinbydefault)\n  * [@ikki](https://twitter.com/_ikki)\n  * [@Caligin35](https://twitter.com/Caligin35)\n  * [@greenfile](https://github.com/greenfile)\n\n\n## Release Notes\n\n### Version 2.0.0beta.2\n * Added check for AJP Tomcat GhostCat (CVE-2020-1938)\n * Improve detection for Apache Tomcat EoL \n * Improved Jackson CVE-2017-7525 deserialization flaw\n * Improved EL Injection detection to minimize FP\n * Improved JBoss Seam 2 Remote Command Execution (thanks to https://github.com/greenfile)\n * Added check for Spring Cloud Path Traversal CVE-2020-5410\n\n### Version 2.0.0beta (9 Jan, 2020):\n * Major improved on scan time performance\n * Added check for Spring Data Commons Remote Code Execution (CVE-2018-1273)\n * Added check for PrimeFaces Expression Language Injection (CVE-2017-1000486)\n * Added check for Spring Data REST - Remote Command Execution (CVE-2017-8046)\n * Added check for Eclipse Mojarra Path Traversal (CVE-2018-14371)\n * Added check for Tomcat URI Normalization found by [@orange_8361](https://twitter.com/orange_8361)\n * Added check for Fastjson RCE (CVE-2017-7525)\n * Added check for Apache SOLR (CVE-2017-12629)\n * Added check for EL3 Injection\n * Added check for Apache Struts Showcase\n * Added check for Apache Struts2 S2-043\n * Added check for Apache Struts2 S2-052\n * Added strategy to bypass weak ACL URI restrictions\n * Added check for SSRF Scanner\n * Added check for REST API Swagger Scanner\n * Added check for Oracle EBS SSRF Vulnerabilities (CVE-2018-3167, CVE-2017-10246)\n * Added check for Next.js Path Traversal Vulnerability (CVE-2018-6184)\n * Added check for NodeJs Path Traversal (2017-14849)\n * Added check check for Session Fixation\n * Added check for session id in url\n * Added check for Javascript PostMessage detection\n * Added check for JBoss HTTP Invoker ReadOnlyAccessFilter CVE-2017-12149\n * Added check for NodeJS Path Traversal CVE-2017-14849\n * Added check for new base check for EL issue\n * Added check for JBoss WS JUDDI console\n * Added check for Oracle iDOC Injection (CVE-2013-3770)\n * Added check for HTTP Open Proxy Detection\n * Improved detection for XXE attacks on xml parameters\n * Improved detection on local file include/path traversal on J2EE env\n * Improve detection for CVE-2014-3625 - Spring Directory Traversal\n * Improve detection for LFI attacks\n * Improve detection for Java Server Faces Path Traversal\n * Improved detection for Infrastructural Path Traversal\n * Improved Spring Boot Actuator\n * Improved check for Apache Axis Admin Console\n\n\n### Version 1.2.5 (29 May, 2016):\n * Added check for UTF8 Response Splitting\n * Added check for JBoss Undertow Directory Traversal (CVE-2014-7816)\n * Added check for NodeJS HTTP Redirect (CVE-2015-1164)\n * Added check for NodeJS HTTP Response Splitting (CVE-2016-2216)\n * Added check for JK Management Endpoints\n * Added check for Pivotal Spring Traversal (CVE-2014-3625)\n * Added check for JBoss jBPM Admin Consoles\n * Adedd check for Apache Struts 2 S2-032 (CVE-2016-3081)\n * Improved LFI payloads\n * Improved EL Injection tests\n * Improved WS Axis security checks\n\n\n### Version 1.2.4 (26 Nov, 2015):\n * Added check for Spring Boot Actuator console\n * Improved LFI module with new UTF-8 payloads\n * Improved EL Injection with new payloads\n * Added check for Apache Roller OGNL Injection (CVE-2013-4212)\n * Added check for Apache Struts 2 S2-023 - thanks to [@h3xstream](https://twitter.com/h3xstream)\n * Added check for Weblogic Admin Console Weak Password\n * Added check for Oracle Application Server multiple file disclosure issues\n * Added check for Oracle Log Database Accessible\n * Added check for AJP service identification\n * Added check for Weblogic UDDI Explorer SSRF (CVE-2014-4210)\n * Improved performance for passive checks\n * Improved Apache Wicket Information Disclosure\n * Improved J2EE incorrect exception handling\n * Added check for End Of Life Software - Jetty\n * Added check for End Of Life Software - Tomcat\n * Added check for End Of Life Software - Oracle Application Server\n * Added check for Oracle Application Server version\n * Added check for Oracle Glassfish version\n * Added check for Oracle Weblogic version\n * Added check Apache Struts OGNL Console\n * Added check for Happy Axis\n\n \n### Version 1.2.3dev (26 Feb, 2015):\n * Added check for Jetty Remote Leak Shared Buffers (CVE-2015-2080) found by [@gdssecurity](https://twitter.com/gdssecurity/)\n * Improved check for Information Disclosure Issues - Remote JVM version\n * Added check for Apache Wicket Arbitrary Resource Access\n * Added check for Incorrect Error Handling - Apache Tapestry\n * Added check for Incorrect Error Handling - Grails\n * Added check for Incorrect Error Handling - GWT\n * Fixed references for EL Injection issue\n\n### Version 1.2.2dev (23 Feb, 2015):\n * Added check for Information Disclosure Issues - Remote JVM version\n * Added check for Information Disclosure Issues - Apache Tomcat version\n * Added check for weak password on HTTP Authentication\n * Fix some bugs on issues reporting\n\n### Version 1.2.1dev (16 Feb, 2015):\n * Improved LFI checks\n * Added initial support for compliance checks\n\n### Version 1.2 (25 Jan, 2015):\n * Added checks for Apache Axis2\n * Added checks for Jboss Admin Console Weak Password\n * Added checks for Jboss JMX Invoker\n * Added checks for Status Servlet\n * Added checks for Snoop Resources\n * Added checks for Apache Tomcat Host Manager Console\n * Multiple bug fixes\n * Pushed [BApp Store](https://pro.portswigger.net/bappstore/). \n\n### Version 1.1.2 (18 Oct, 2014):\n * Initial Public Release\n \n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Filmila%2FJ2EEScan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Filmila%2FJ2EEScan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Filmila%2FJ2EEScan/lists"}