cbcvebase.

Redhat Jboss Enterprise Application Platform vulnerabilities

241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.

Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17

Vulnerabilities

Page 12 of 13
CVE-2010-3878P4MEDIUMCVSS 4.3v4.3.02010-12-30
CVE-2010-3878 [MEDIUM] CWE-352 CVE-2010-3878: Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Appli Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests that deploy WAR files.
nvd
CVE-2019-14885P4MEDIUMCVSS 4.3fixed in 7.2.6v7.2.62020-01-23
CVE-2019-14885 [MEDIUM] CWE-532 CVE-2019-14885: A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential informa A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.
nvd
CVE-2014-7827P4LOWCVSS 3.5≤ 6.3.22015-02-13
CVE-2014-7827 [LOW] CWE-264 CVE-2014-7827: The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red H The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain
nvd
CVE-2009-2405P4MEDIUMCVSS 4.3v4.2v4.2.0+4 more2009-12-15
CVE-2009-2405 [MEDIUM] CWE-79 CVE-2009-2405: Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribut
nvd
CVE-2014-7853P4MEDIUMCVSS 4.0≤ 6.3.22015-02-13
CVE-2014-7853 [MEDIUM] CWE-200 CVE-2014-7853: The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Plat The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribut
nvd
CVE-2015-5304P4LOWCVSS 3.5≤ 6.4.42015-12-16
CVE-2015-5304 [LOW] CWE-264 CVE-2015-5304: Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.
nvd
CVE-2026-4874P4LOWCVSS 3.1v8.0.02026-03-26
CVE-2026-4874 [LOW] CWE-918 CVE-2026-4874: A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSR A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the a
nvd
CVE-2010-4265P4LOWCVSS 2.6v4.3.0v5.1.02010-12-30
CVE-2010-4265 [LOW] CVE-2010-4265: The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run meth The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket
nvd
CVE-2014-0005P4LOWCVSS 3.6v6.2.22015-02-20
CVE-2014-0005 [LOW] CWE-264 CVE-2014-0005: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JB PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
nvd
CVE-2010-3862P4LOWCVSS 2.6v4.3.0v5.1.02010-12-30
CVE-2010-3862 [LOW] CWE-20 CVE-2010-3862: The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run meth The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers
nvd
CVE-2012-4572P4LOWCVSS 3.7≤ 6.0.1v4.2.0+10 more2013-10-28
CVE-2012-4572 [LOW] CWE-264 CVE-2012-4572: Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted ap
nvd
CVE-2013-0218P4LOWCVSS 2.1v5.1.2v5.2.02013-02-05
CVE-2013-0218 [LOW] CWE-200 CVE-2013-0218: The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5 The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.
nvd
CVE-2012-0034P4LOWCVSS 2.1v5.1.2v5.2.02013-02-05
CVE-2012-0034 [LOW] CWE-255 CVE-2012-0034: The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
nvd
CVE-2009-5066P4LOWCVSS 2.1v5.0.02012-08-13
CVE-2009-5066 [LOW] CWE-255 CVE-2009-5066: twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, wh twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
nvd
CVE-2014-0018P4LOWCVSS 1.9v6.2.02014-02-14
CVE-2014-0018 [LOW] CWE-264 CVE-2014-0018: Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, wh Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.
nvd
CVE-2009-3554P4LOWCVSS 2.1v4.2v4.2.0+1 more2009-12-15
CVE-2009-3554 [LOW] CWE-200 CVE-2009-3554: Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.C Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.
nvd
CVE-2014-3586P4LOWCVSS 2.1≤ 6.3.32015-04-21
CVE-2014-3586 [LOW] CWE-264 CVE-2014-3586: The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2012-3427P4LOWCVSS 2.1v5.1.22014-02-02
CVE-2012-3427 [LOW] CWE-264 CVE-2012-3427: EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permiss EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
nvd
CVE-2014-0058P4LOWCVSS 1.9v6.0.0v6.0.1+2 more2014-02-26
CVE-2014-0058 [LOW] CWE-310 CVE-2014-0058: The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6 The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
nvd
CVE-2013-1921P4LOWCVSS 1.9≤ 6.1.0v4.2.0+11 more2013-09-28
CVE-2013-1921 [LOW] CWE-310 CVE-2013-1921: PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
nvd
Redhat Jboss Enterprise Application Platform vulnerabilities | cvebase