Redhat Jboss Enterprise Application Platform vulnerabilities
241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.
Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17
Vulnerabilities
Page 11 of 13
CVE-2019-14838P4MEDIUMCVSS 4.9v7.2.0v7.2.5+2 more2019-10-14
CVE-2019-14838 [MEDIUM] CWE-284 CVE-2019-14838: A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Dep
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
nvd
CVE-2020-10687P4MEDIUMCVSS 4.8v7.2v7.3+1 more2020-09-23
CVE-2020-10687 [MEDIUM] CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request sm
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other tha
nvd
CVE-2015-5220P4MEDIUMCVSS 5.0≤ 6.4.32015-10-27
CVE-2015-5220 [MEDIUM] CWE-119 CVE-2015-5220: The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
nvd
CVE-2011-4610P4MEDIUMCVSS 5.0≤ 5.1.22014-02-10
CVE-2011-4610 [MEDIUM] CWE-119 CVE-2011-4610: JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform be
JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an int
nvd
CVE-2018-10934P4MEDIUMCVSS 5.4v7.0v7.1.02019-03-27
CVE-2018-10934 [MEDIUM] CWE-79 CVE-2018-10934: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
nvd
CVE-2019-3872P4MEDIUMCVSS 5.4v7.2.02019-06-12
CVE-2019-3872 [MEDIUM] CWE-79 CVE-2019-3872: It was found that a SAMLRequest containing a script could be processed by Picketlink versions shippe
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
nvd
CVE-2017-12167P4MEDIUMCVSS 5.5fixed in 7.0.9v7.1.0+1 more2018-07-26
CVE-2017-12167 [MEDIUM] CWE-732 CVE-2017-12167: It was found in EAP 7 before 7.0.9 that properties based files of the management and the application
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
nvd
CVE-2016-9585P4MEDIUMCVSS 5.3v5.0.02018-03-09
CVE-2016-9585 [MEDIUM] CWE-502 CVE-2016-9585: Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.
nvd
CVE-2013-4210P4MEDIUMCVSS 5.0v5.0.02013-10-01
CVE-2013-4210 [MEDIUM] CVE-2013-4210: The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBo
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.
nvd
CVE-2019-14820P4MEDIUMCVSS 4.3v6.4.0v7.2.02020-01-08
CVE-2019-14820 [MEDIUM] CWE-200 CVE-2019-14820: It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.c
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
nvd
CVE-2012-4529P4MEDIUMCVSS 4.3v6.0.02013-10-28
CVE-2012-4529 [MEDIUM] CVE-2012-4529: The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier,
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
nvd
CVE-2021-3536P4MEDIUMCVSS 4.8v7.02021-05-20
CVE-2021-3536 [MEDIUM] CWE-79 CVE-2021-3536: A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
nvd
CVE-2019-3805P4MEDIUMCVSS 4.7v6.0.0v7.0.02019-05-03
CVE-2019-3805 [MEDIUM] CWE-364 CVE-2019-3805: A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are ab
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
nvd
CVE-2014-7849P4MEDIUMCVSS 4.0v6.2.0v6.2.1+6 more2015-02-13
CVE-2014-7849 [MEDIUM] CWE-264 CVE-2014-7849: The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
nvd
CVE-2022-2764P4MEDIUMCVSS 4.9v7.0.02022-09-01
CVE-2022-2764 [MEDIUM] CWE-400 CVE-2022-2764: A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAS
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
nvd
CVE-2011-4575P4MEDIUMCVSS 4.3v5.2.02013-02-05
CVE-2011-4575 [MEDIUM] CWE-20 CVE-2011-4575: Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-5178P4MEDIUMCVSS 4.3≤ 6.4.32015-10-27
CVE-2015-5178 [MEDIUM] CWE-254 CVE-2015-5178: The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
nvd
CVE-2020-1732P4MEDIUMCVSS 4.2v7.0.02020-05-04
CVE-2020-1732 [MEDIUM] CWE-284 CVE-2020-1732: A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently cau
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
nvd
CVE-2009-1380P4MEDIUMCVSS 4.3v4.2v4.2.0+2 more2009-12-15
CVE-2009-1380 [MEDIUM] CWE-79 CVE-2009-1380: Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Appli
Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters.
nvd
CVE-2008-3519P4MEDIUMCVSS 4.3≤ 4.2≤ 4.3+2 more2008-09-23
CVE-2008-3519 [MEDIUM] CVE-2008-3519: The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform
The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request
nvd