cbcvebase.

Redhat Jboss Enterprise Application Platform vulnerabilities

241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.

Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17

Vulnerabilities

Page 6 of 13
CVE-2014-0248P3MEDIUMCVSS 6.8v5.2.02014-07-07
CVE-2014-0248 [MEDIUM] CWE-94 CVE-2014-0248: org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise A org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
nvd
CVE-2013-2185P3HIGHCVSS 7.5v6.1.02014-01-19
CVE-2013-2185 [HIGH] CWE-20 CVE-2013-2185: The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat J The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly dispute
nvd
CVE-2020-14299P3MEDIUMCVSS 6.5fixed in 5.0.32020-10-16
CVE-2020-14299 [MEDIUM] CWE-287 CVE-2020-14299: A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy Secur A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is
nvd
CVE-2020-7238P3HIGHCVSS 7.5v7.2v7.3+1 more2020-01-27
CVE-2020-7238 [HIGH] CVE-2020-7238: Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
nvd
CVE-2021-3717P3HIGHCVSS 7.8v7.4v7.32022-05-24
CVE-2021-3717 [HIGH] CWE-552 CVE-2021-3717: A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
nvd
CVE-2022-3143P3HIGHCVSS 7.4v7.0.02023-01-13
CVE-2022-3143 [HIGH] CWE-203 CVE-2022-3143: wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-e wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure informatio
nvd
CVE-2019-14900P3MEDIUMCVSS 6.5v7.3v7.4+1 more2020-07-06
CVE-2019-14900 [MEDIUM] CWE-89 CVE-2019-14900: A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks
nvd
CVE-2014-0118P3MEDIUMCVSS 4.3v6.0.0v6.4.02014-07-20
CVE-2014-0118 [MEDIUM] CWE-400 CVE-2014-0118: The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
nvd
CVE-2021-32029P3MEDIUMCVSS 6.5v7.0.02021-10-08
CVE-2021-32029 [MEDIUM] CWE-200 CVE-2021-32029: A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2011-4605P3HIGHCVSS 7.5v4.3.0v5.1.22012-11-23
CVE-2011-4605 [HIGH] CWE-264 CVE-2011-4605: The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to
nvd
CVE-2026-3260P3HIGHCVSS 7.5v7.0.0v8.0.02026-03-24
CVE-2026-3260 [HIGH] CWE-770 CVE-2026-3260: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentiall
nvd
CVE-2023-1108P3HIGHCVSS 7.5v7.42023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd
CVE-2016-8657P3HIGHCVSS 7.8v6.0.0v6.4.0+1 more2018-07-31
CVE-2016-8657 [HIGH] CWE-264 CVE-2016-8657: It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect pe It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init scri
nvd
CVE-2023-5379P3HIGHCVSS 7.5v7.0.02023-12-12
CVE-2023-5379 [HIGH] CWE-770 CVE-2023-5379: A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when t
nvd
CVE-2014-3518P3MEDIUMCVSS 6.8v5.2.02014-07-22
CVE-2014-3518 [MEDIUM] CWE-94 CVE-2014-3518: jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-12174P3HIGHCVSS 7.5v6.4.0v7.1.0+1 more2018-03-07
CVE-2017-12174 [HIGH] CWE-400 CVE-2017-12174: It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroup It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.
nvd
CVE-2017-12165P3HIGHCVSS 7.5v7.0.0v7.1.02018-07-27
CVE-2017-12165 [HIGH] CWE-444 CVE-2017-12165: It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
nvd
CVE-2018-1048P3HIGHCVSS 7.5v7.1.02018-01-24
CVE-2018-1048 [HIGH] CWE-22 CVE-2018-1048: It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
nvd
CVE-2016-8656P3HIGHCVSS 7.8v5.0.0v6.0.0+3 more2018-05-22
CVE-2016-8656 [HIGH] CWE-284 CVE-2016-8656: Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in th Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
nvd
CVE-2012-5626P3HIGHCVSS 7.5v5.0.02020-01-23
CVE-2012-5626 [HIGH] CVE-2012-5626: EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss O EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
nvd
Redhat Jboss Enterprise Application Platform vulnerabilities | cvebase