cbcvebase.

Redhat Jboss Enterprise Application Platform vulnerabilities

241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.

Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17

Vulnerabilities

Page 4 of 13
CVE-2016-5406P3HIGHCVSS 8.8≤ 7.0.12016-09-26
CVE-2016-5406 [HIGH] CWE-264 CVE-2016-5406: The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
nvd
CVE-2018-8039P3HIGHCVSS 8.1v7.1.02018-07-02
CVE-2018-8039 [HIGH] CWE-755 CVE-2018-8039: It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProp It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the defaul
nvd
CVE-2018-1336P3HIGHCVSS 7.5v6.0.0v6.4.02018-08-02
CVE-2018-1336 [HIGH] CWE-835 CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an in An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
nvd
CVE-2018-12022P3HIGHCVSS 7.5v7.2.02019-03-21
CVE-2018-12022 [HIGH] CWE-502 CVE-2018-12022: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the servic
nvd
CVE-2019-16335P3CRITICALCVSS 9.8v7.2v7.32019-09-15
CVE-2019-16335 [CRITICAL] CVE-2019-16335: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
nvd
CVE-2016-2141P3CRITICALCVSS 9.8v5.2v6.4+1 more2016-06-30
CVE-2016-2141 [CRITICAL] CVE-2016-2141: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
nvd
CVE-2019-17267P3CRITICALCVSS 9.8v7.2v7.32019-10-07
CVE-2019-17267 [CRITICAL] CWE-502 CVE-2019-17267: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
nvd
CVE-2019-10212P3CRITICALCVSS 9.8v7.2v7.3+1 more2019-10-02
CVE-2019-10212 [CRITICAL] CWE-532 CVE-2019-10212: A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. I A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
nvd
CVE-2016-4978P3HIGHCVSS 7.2v6.0.0v6.4.0+2 more2016-09-27
CVE-2016-4978 [HIGH] CWE-502 CVE-2016-4978: The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis br The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget cla
nvd
CVE-2019-10202P3CRITICALCVSS 9.8v7.2.02019-10-01
CVE-2019-10202 [CRITICAL] CVE-2019-10202: A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EA A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and futur
nvd
CVE-2019-0205P3HIGHCVSS 7.5v7.2.02019-10-29
CVE-2019-0205 [HIGH] CWE-835 CVE-2019-0205: In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
nvd
CVE-2019-10174P3HIGHCVSS 8.8v7.22019-11-25
CVE-2019-10174 [HIGH] CWE-470 CVE-2019-10174: A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
nvd
CVE-2019-14843P3HIGHCVSS 8.8v7.2.02020-01-07
CVE-2019-14843 [HIGH] CWE-592 CVE-2019-14843: A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests fo A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.
nvd
CVE-2016-6796P3HIGHCVSS 7.5v6.42017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2018-1000632P3HIGHCVSS 7.5v6.0.0v6.4.0+1 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2014-3490P3HIGHCVSS 7.5v6.3.02014-08-19
CVE-2014-3490 [HIGH] CVE-2014-3490: RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Applicatio RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to a
nvd
CVE-2012-5629P3HIGHCVSS 7.5v4.3.0v5.2.0+1 more2013-03-12
CVE-2012-5629 [HIGH] CWE-264 CVE-2012-5629: The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Ent The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.
nvd
CVE-2013-1862P3MEDIUMCVSS 5.1v6.0.0v6.4.02013-06-10
CVE-2013-1862 [MEDIUM] CVE-2013-1862: mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
nvd
CVE-2019-3894P3HIGHCVSS 8.8v7.0.02019-05-03
CVE-2019-3894 [HIGH] CWE-358 CVE-2019-3894: It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 t It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.
nvd
CVE-2025-9784P3HIGHCVSS 7.5v7.0.0v8.0.02025-09-02
CVE-2025-9784 [HIGH] CWE-770 CVE-2025-9784: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets w A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implem
nvd
Redhat Jboss Enterprise Application Platform vulnerabilities | cvebase