VYPR
Vendor

JBoss

Products
31
CVEs
49
Across products
56
Status
Private

Products

31
View all 31 products →

Recent CVEs

49
View all 49 CVEs →
  • CVE-2016-3690CriJun 8, 2017
    risk 0.64cvss 9.8epss 0.05

    The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

  • CVE-2018-1041HigFeb 15, 2018
    risk 0.53cvss 7.5epss 0.16

    A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

  • CVE-2010-0737HigOct 30, 2019
    risk 0.52cvss 8.0epss 0.01

    A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

  • CVE-2012-2312HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.00

    An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user…

  • CVE-2016-7066HigSep 11, 2018
    risk 0.51cvss 7.8epss 0.00

    It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.

  • CVE-2016-6325HigOct 13, 2016
    risk 0.51cvss 7.8epss 0.01

    The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

  • CVE-2023-5379HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens…

  • CVE-2022-0853HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

  • CVE-2016-2094HigMay 6, 2016
    risk 0.49cvss 7.5epss 0.03

    The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

  • CVE-2019-3834HigOct 3, 2019
    risk 0.48cvss 7.3epss 0.01

    It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as…

  • CVE-2016-8656HigMay 22, 2018
    risk 0.46cvss 7.0epss 0.00

    Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.

  • CVE-2013-3734MedOct 24, 2017
    risk 0.43cvss 6.6epss 0.02

    The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain…

  • CVE-2020-14299MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using…

  • CVE-2014-0169MedJan 2, 2020
    risk 0.42cvss 6.5epss 0.01

    In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization.…

  • CVE-2011-3609MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user…

  • CVE-2008-5083MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

  • CVE-2019-3873MedJun 12, 2019
    risk 0.42cvss 6.4epss 0.01

    It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

  • CVE-2025-2251MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.01

    A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a…

  • CVE-2014-3649MedNov 4, 2019
    risk 0.40cvss 6.1epss 0.01

    JBoss AeroGear has reflected XSS via the password field

  • CVE-2016-6343MedOct 31, 2018
    risk 0.40cvss 6.1epss 0.02

    JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation…