VYPR

Jboss Enterprise Application Platform

by Red Hat

CVEs (249)

  • CVE-2024-1102MedApr 25, 2024
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

  • CVE-2023-3628MedDec 18, 2023
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

  • CVE-2023-4061MedNov 8, 2023
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from…

  • CVE-2022-0866MedMay 10, 2022
    risk 0.35cvss 5.3epss 0.01

    This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field…

  • CVE-2021-3642MedAug 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.

  • CVE-2020-25689MedNov 2, 2020
    risk 0.35cvss 5.3epss 0.01

    A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out…

  • CVE-2020-1710MedSep 16, 2020
    risk 0.35cvss 5.3epss 0.01

    The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

  • CVE-2019-14900MedJul 6, 2020
    risk 0.35cvss 6.5epss 0.02

    A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an…

  • CVE-2020-10693MedMay 6, 2020
    risk 0.35cvss 5.3epss 0.02

    A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers…

  • CVE-2019-3872MedJun 12, 2019
    risk 0.35cvss 5.4epss 0.01

    It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or…

  • CVE-2018-10934MedMar 27, 2019
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

  • CVE-2018-14642MedSep 18, 2018
    risk 0.35cvss 5.3epss 0.02

    An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.

  • CVE-2016-9585MedMar 9, 2018
    risk 0.35cvss 5.3epss 0.01

    Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.

  • CVE-2016-6311MedAug 22, 2017
    risk 0.35cvss 5.3epss 0.02

    Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

  • CVE-2012-4550MedJan 5, 2013
    risk 0.35cvss 5.3epss 0.02

    A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC)…

  • CVE-2019-10219MedNov 8, 2019
    risk 0.33cvss 6.1epss 0.02

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

  • CVE-2018-1304MedFeb 28, 2018
    risk 0.33cvss 5.9epss 0.17

    The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the…

  • CVE-2016-4993MedSep 26, 2016
    risk 0.33cvss 6.1epss 0.03

    CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified…

  • CVE-2022-2764MedSep 1, 2022
    risk 0.32cvss 4.9epss 0.01

    A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

  • CVE-2016-7046MedOct 3, 2016
    risk 0.32cvss 5.9epss 0.02

    Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.

Page 8 of 13