cbcvebase.

Redhat Jboss Enterprise Application Platform vulnerabilities

241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.

Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17

Vulnerabilities

Page 8 of 13
CVE-2022-1259P3HIGHCVSS 7.5v7.0.02022-08-31
CVE-2022-1259 [HIGH] CVE-2022-1259: A flaw was found in Undertow. A potential security issue in flow control handling by the browser ove A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
nvd
CVE-2013-4213P3MEDIUMCVSS 6.4v6.1.02013-08-16
CVE-2013-4213 [MEDIUM] CWE-284 CVE-2013-4213: Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
nvd
CVE-2013-4128P3MEDIUMCVSS 6.4v6.1.02013-08-16
CVE-2013-4128 [MEDIUM] CWE-16 CVE-2013-4128: Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
nvd
CVE-2014-0034P3MEDIUMCVSS 4.3v6.0.0v6.2.02014-07-07
CVE-2014-0034 [MEDIUM] CWE-20 CVE-2014-0034: The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
nvd
CVE-2024-1102P3MEDIUMCVSS 6.5v8.02024-04-25
CVE-2024-1102 [MEDIUM] CWE-523 CVE-2024-1102: A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
nvd
CVE-2017-12196P3MEDIUMCVSS 5.9v7.0.02018-04-18
CVE-2017-12196 [MEDIUM] CWE-287 CVE-2017-12196: undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Diges undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v6.0.0v6.4.0+1 more2018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2017-12189P4HIGHCVSS 7.8v7.02018-01-10
CVE-2017-12189 [HIGH] CVE-2017-12189: It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platfor It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.
nvd
CVE-2011-1484P4MEDIUMCVSS 6.8v4.3.0v5.1.02011-07-27
CVE-2011-1484 [MEDIUM] CWE-264 CVE-2011-1484: jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Ente jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, whic
nvd
CVE-2017-2582P4MEDIUMCVSS 6.5v6.0.0v6.4.0+2 more2018-07-26
CVE-2017-2582 [MEDIUM] CWE-201 CVE-2017-2582: It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which coul
nvd
CVE-2020-10719P4MEDIUMCVSS 6.5v7.3v7.4+1 more2020-05-26
CVE-2020-10719 [MEDIUM] CWE-444 CVE-2020-10719: A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTT A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
nvd
CVE-2023-4061P4MEDIUMCVSS 6.5v7.42023-11-08
CVE-2023-4061 [MEDIUM] CWE-200 CVE-2023-4061: A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Inte A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system.
nvd
CVE-2023-3628P3MEDIUMCVSS 6.5v62023-12-18
CVE-2023-3628 [MEDIUM] CWE-304 CVE-2023-3628: A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
nvd
CVE-2023-3629P4MEDIUMCVSS 6.5v62023-12-18
CVE-2023-3629 [MEDIUM] CWE-304 CVE-2023-3629: A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necess A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
nvd
CVE-2014-0093P4MEDIUMCVSS 5.8v6.2.22014-04-03
CVE-2014-0093 [MEDIUM] CWE-264 CVE-2014-0093: Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
nvd
CVE-2020-10705P4HIGHCVSS 7.5v7.22020-06-10
CVE-2020-10705 [HIGH] CWE-770 CVE-2020-10705: A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
nvd
CVE-2017-2666P4MEDIUMCVSS 6.5v7.0.0v7.1.02018-07-27
CVE-2017-2666 [MEDIUM] CWE-444 CVE-2017-2666: It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid char It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache,
nvd
CVE-2012-4549P4MEDIUMCVSS 6.5≤ 6.0.0v4.2.0+9 more2013-01-05
CVE-2012-4549 [MEDIUM] CWE-266 CVE-2012-4549: A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within t A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB m
nvd
CVE-2014-0169P4MEDIUMCVSS 6.5v6.0.02020-01-02
CVE-2014-0169 [MEDIUM] CWE-863 CVE-2014-0169: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all application In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented whi
nvd
CVE-2026-4366P4MEDIUMCVSS 5.8v8.0.02026-03-18
CVE-2026-4366 [MEDIUM] CWE-918 CVE-2026-4366: A flaw was identified in Keycloak, an identity and access management solution, where it improperly f A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud
nvd
Redhat Jboss Enterprise Application Platform vulnerabilities | cvebase