Redhat Jboss Application Server vulnerabilities
5 known vulnerabilities affecting redhat/jboss_application_server.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2012-1094HIGHCVSS 7.5≥ 7.0.0, < 7.1.12020-03-10
CVE-2012-1094 [HIGH] CWE-200 CVE-2012-1094: JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
nvd
CVE-2012-2312HIGHCVSS 7.8v7.1.0v7.1.12019-12-18
CVE-2012-2312 [HIGH] CWE-269 CVE-2012-2312: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementati
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
nvd
CVE-2011-3606MEDIUMCVSS 5.4v7.0.0v7.0.1+1 more2019-11-26
CVE-2011-3606 [MEDIUM] CWE-79 CVE-2011-3606: A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web scrip
nvd
CVE-2011-3609MEDIUMCVSS 6.5v7.0.0v7.0.1+1 more2019-11-26
CVE-2011-3609 [MEDIUM] CWE-352 CVE-2011-3609: A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict a
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a re
nvd
CVE-2013-3734MEDIUMCVSS 6.6≤ 1.22017-10-24
CVE-2013-3734 [MEDIUM] CWE-255 CVE-2013-3734: The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password i
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code. NOTE: the vendor says that
nvd