VYPR

Jboss Enterprise Application Platform Continuous Delivery

by Red Hat

Source repositories

CVEs (4)

  • CVE-2020-14307MedJul 24, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows…

  • CVE-2020-14317MedJun 2, 2021
    risk 0.36cvss 5.5epss 0.00

    It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/…

  • CVE-2020-14297MedJul 24, 2020
    risk 0.35cvss 6.5epss 0.01

    A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of…

  • CVE-2020-1732MedMay 4, 2020
    risk 0.00cvss 4.2epss 0.01

    A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from…