VYPR

EAP 7

by Red Hat

CVEs (6)

  • CVE-2026-86404HigSep 7, 2026
    risk 0.57cvss 8.8epss 0.01

    EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list…

  • CVE-2023-3171HigDec 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the…

  • CVE-2026-15563HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

  • CVE-2017-12167MedJul 26, 2018
    risk 0.36cvss 5.5epss 0.00

    It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

  • CVE-2026-85511MedSep 18, 2026
    risk 0.27cvss 4.2epss 0.00

    A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

  • CVE-2016-7061LowSep 10, 2018
    risk 0.23cvss 3.5epss 0.02

    An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.