VYPR

by Red Hat

Source repositories

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-5183Hig0.497.50.00Sep 25, 2017Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
CVE-2015-5181Med0.355.40.00Sep 25, 2017The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
CVE-2014-00850.000.00Apr 17, 2014JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.
CVE-2013-43720.000.00Sep 30, 2013Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.