VYPR

DataGrid

by Red Hat

CVEs (45)

  • CVE-2026-15945MedJul 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching…

  • CVE-2019-14838MedOct 14, 2019
    risk 0.25cvss 4.9epss 0.01

    A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

  • CVE-2023-5236MedDec 18, 2023
    risk 0.22cvss 4.4epss 0.01

    A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial…

  • CVE-2023-3629MedDec 18, 2023
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.

  • CVE-2017-2638MedJul 16, 2018
    risk 0.00cvss 6.5epss 0.02

    It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.

Page 3 of 3