Redhat Jboss Enterprise Application Platform vulnerabilities
241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.
Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
18
Exploited in wild
8
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17
Vulnerabilities
Page 8 of 13
CVE-2018-1047MEDIUMCVSS 5.5v7.1.02018-01-24
CVE-2018-1047 [MEDIUM] CWE-20 CVE-2018-1047: A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.un
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
nvd
CVE-2018-5968HIGHCVSS 8.1v7.12018-01-22
CVE-2018-5968 [HIGH] CVE-2018-5968: FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
nvd
CVE-2017-17485CRITICALCVSS 9.8v6.0.0v6.4.0+1 more2018-01-10
CVE-2017-17485 [CRITICAL] CWE-502 CVE-2017-17485: FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring li
nvd
CVE-2017-12189HIGHCVSS 7.8v7.02018-01-10
CVE-2017-12189 [HIGH] CVE-2017-12189: It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platfor
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
nvd
CVE-2017-7536HIGHCVSS 7.0v6.0.0v6.4.0+2 more2018-01-10
CVE-2017-7536 [HIGH] CWE-592 CVE-2017-7536: In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the securi
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permi
nvd
CVE-2016-8610HIGHCVSS 7.5v6.0.0v6.4.02017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2015-7501CRITICALCVSS 9.8v4.3.0v5.0.0+1 more2017-11-09
CVE-2015-7501 [CRITICAL] CWE-502 CVE-2015-7501: Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualiza
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Ha
nvd
CVE-2017-12629CRITICALCVSS 9.8ExploitedPoCv7.0.0v7.1.02017-10-14
CVE-2017-12629 [CRITICAL] CWE-611 CVE-2017-12629: Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting X
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML
nvd
CVE-2017-12149CRITICALCVSS 9.8KEVPoCv5.0.0v5.0.1+6 more2017-10-04
CVE-2017-12149 [CRITICAL] CWE-502 CVE-2017-12149: In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was foun
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoCv6.0.0v6.4.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2015-1849MEDIUMCVSS 5.9≤ 6.4.02017-09-19
CVE-2015-1849 [MEDIUM] CWE-200 CVE-2015-1849: AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows a
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
nvd
CVE-2017-7561HIGHCVSS 7.5v3.0.7v3.0.8+12 more2017-09-13
CVE-2017-7561 [HIGH] CWE-346 CVE-2017-7561: Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache pois
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.
nvd
CVE-2016-6311MEDIUMCVSS 5.3v7.02017-08-22
CVE-2016-6311 [MEDIUM] CWE-200 CVE-2016-6311: Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remo
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
nvd
CVE-2016-6796HIGHCVSS 7.5v6.42017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2016-5018CRITICALCVSS 9.1PoCv6.42017-08-10
CVE-2016-5018 [CRITICAL] CVE-2016-5018: In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
nvd
CVE-2017-9788CRITICALCVSS 9.1v6.0.0v6.4.02017-07-13
CVE-2017-9788 [CRITICAL] CWE-20 CVE-2017-9788: In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorizatio
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior
nvd
CVE-2016-3690CRITICALCVSS 9.8v4.2.0v4.3.0+5 more2017-06-08
CVE-2016-3690 [CRITICAL] CWE-502 CVE-2016-3690: The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
nvd
CVE-2017-7504CRITICALCVSS 9.8≤ 4.02017-05-19
CVE-2017-7504 [CRITICAL] CWE-502 CVE-2017-7504: HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is e
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized data.
nvd
CVE-2017-7503CRITICALCVSS 9.8v7.0.52017-05-18
CVE-2017-7503 [CRITICAL] CWE-611 CVE-2017-7503: It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFacto
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
nvd
CVE-2016-7065HIGHCVSS 8.8PoCv4.0.0v5.0.02016-10-13
CVE-2016-7065 [HIGH] CWE-502 CVE-2016-7065: The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authent
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
nvd