cbcvebase.

Redhat Jboss Enterprise Application Platform vulnerabilities

241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.

Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17

Vulnerabilities

Page 7 of 13
CVE-2023-3171P3HIGHCVSS 7.5v7.42023-12-27
CVE-2023-3171 [HIGH] CWE-789 CVE-2023-3171: A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
nvd
CVE-2017-2595P3MEDIUMCVSS 6.5v6.0.0v6.4.0+2 more2018-07-27
CVE-2017-2595 [MEDIUM] CWE-22 CVE-2017-2595: It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitra It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
nvd
CVE-2025-23367P3MEDIUMCVSS 6.5≥ 7.4, < 7.4.21≥ 8.0.0, < 8.0.72025-01-30
CVE-2025-23367 [MEDIUM] CWE-284 CVE-2025-23367: A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions
nvd
CVE-2017-2670P3HIGHCVSS 7.5v6.0.0v7.0.0+1 more2018-07-27
CVE-2017-2670 [HIGH] CWE-835 CVE-2017-2670: It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
nvd
CVE-2012-5575P3MEDIUMCVSS 6.4v5.0.02013-08-19
CVE-2012-5575 [MEDIUM] CWE-310 CVE-2012-5575: Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify t Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt commu
nvd
CVE-2013-1896P3MEDIUMCVSS 4.3v6.0.0v6.4.02013-07-10
CVE-2013-1896 [MEDIUM] CVE-2013-1896: mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
nvd
CVE-2020-25644P3HIGHCVSS 7.5v7.0.02020-10-06
CVE-2020-25644 [HIGH] CWE-401 CVE-2020-25644: A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes a A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-14888P3HIGHCVSS 7.5v7.0.02020-01-23
CVE-2019-14888 [HIGH] CWE-400 CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening o A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
nvd
CVE-2019-19343P3HIGHCVSS 7.5fixed in 7.2.42021-03-23
CVE-2019-19343 [HIGH] CWE-400 CVE-2019-19343: A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2. A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
nvd
CVE-2020-14384P3HIGHCVSS 7.5v6.0.02020-09-09
CVE-2020-14384 [HIGH] CVE-2020-14384: A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 wa A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.
nvd
CVE-2016-7066P3HIGHCVSS 7.8fixed in 7.1.02018-09-11
CVE-2016-7066 [HIGH] CWE-266 CVE-2016-7066: It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Applic It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
nvd
CVE-2022-4492P3HIGHCVSS 7.5v7.0.02023-02-23
CVE-2022-4492 [HIGH] CWE-918 CVE-2022-4492: The undertow client is not checking the server identity presented by the server certificate in https The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
nvd
CVE-2017-7561P3HIGHCVSS 7.5v3.0.7v3.0.8+12 more2017-09-13
CVE-2017-7561 [HIGH] CWE-346 CVE-2017-7561: Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache pois Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
nvd
CVE-2022-0853P3HIGHCVSS 7.5v7.0.02022-03-11
CVE-2022-0853 [HIGH] CWE-401 CVE-2022-0853: A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client- A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
nvd
CVE-2021-3859P3HIGHCVSS 7.5v7.3v7.42022-08-26
CVE-2021-3859 [HIGH] CWE-214 CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
nvd
CVE-2012-2312P3HIGHCVSS 7.8v6.0.02019-12-18
CVE-2012-2312 [HIGH] CWE-269 CVE-2012-2312: An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementati An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
nvd
CVE-2011-2196P3MEDIUMCVSS 6.8v4.3.0v5.1.12011-07-27
CVE-2011-2196 [MEDIUM] CVE-2011-2196: jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Ente jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessage
nvd
CVE-2019-3873P3CRITICALCVSS 9.0v7.2.02019-06-12
CVE-2019-3873 [CRITICAL] CWE-79 CVE-2019-3873: It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
nvd
CVE-2016-3110P3HIGHCVSS 7.5v6.0.0v6.4.02016-09-26
CVE-2016-3110 [HIGH] CWE-20 CVE-2016-3110: mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of s mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
nvd
CVE-2021-3690P3HIGHCVSS 7.5v7.3v7.42022-08-23
CVE-2021-3690 [HIGH] CWE-400 CVE-2021-3690: A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memor A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
nvd
Redhat Jboss Enterprise Application Platform vulnerabilities | cvebase