Redhat Jboss Enterprise Application Platform vulnerabilities
241 known vulnerabilities affecting redhat/jboss_enterprise_application_platform.
Total CVEs
241
CISA KEV
6
actively exploited
Public exploits
19
Exploited in wild
17
Severity breakdown
CRITICAL36HIGH86MEDIUM102LOW17
Vulnerabilities
Page 9 of 13
CVE-2016-8627P4MEDIUMCVSS 6.5v6.4.0v7.0.0+1 more2018-05-11
CVE-2016-8627 [MEDIUM] CWE-400 CVE-2016-8627: admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download serve
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impair
nvd
CVE-2017-7536P4HIGHCVSS 7.0v6.0.0v6.4.0+2 more2018-01-10
CVE-2017-7536 [HIGH] CWE-592 CVE-2017-7536: In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the securi
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permi
nvd
CVE-2020-25689P4MEDIUMCVSS 6.5v7.0.02020-11-02
CVE-2020-25689 [MEDIUM] CWE-401 CVE-2020-25689: A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tr
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat
nvd
CVE-2014-3481P4MEDIUMCVSS 5.0≤ 6.2.3v6.0.0+5 more2014-07-07
CVE-2014-3481 [MEDIUM] CWE-200 CVE-2014-3481: org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Plat
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
nvd
CVE-2016-7061P4MEDIUMCVSS 6.5fixed in 7.0.42018-09-10
CVE-2016-7061 [MEDIUM] CWE-200 CVE-2016-7061: An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
nvd
CVE-2018-1067P4MEDIUMCVSS 6.1v7.12018-05-21
CVE-2018-1067 [MEDIUM] CVE-2018-1067: In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was inco
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
nvd
CVE-2012-3370P4MEDIUMCVSS 5.8v5.2.02013-02-05
CVE-2012-3370 [MEDIUM] CWE-264 CVE-2012-3370: The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
nvd
CVE-2012-4550P4MEDIUMCVSS 5.3v6.0.02013-01-05
CVE-2012-4550 [MEDIUM] CWE-280 CVE-2012-4550: A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized a
nvd
CVE-2011-2487P4MEDIUMCVSS 5.9v5.0.02020-03-11
CVE-2011-2487 [MEDIUM] CWE-327 CVE-2011-2487: The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache W
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
nvd
CVE-2015-1849P4MEDIUMCVSS 5.9≤ 6.4.02017-09-19
CVE-2015-1849 [MEDIUM] CWE-200 CVE-2015-1849: AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows a
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
nvd
CVE-2013-4112P4MEDIUMCVSS 5.4v6.1.02013-09-28
CVE-2013-4112 [MEDIUM] CWE-200 CVE-2013-4112: The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows rem
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
nvd
CVE-2012-1154P4MEDIUMCVSS 4.3v5.1.22012-10-22
CVE-2012-1154 [MEDIUM] CWE-264 CVE-2012-1154: mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Applicatio
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
nvd
CVE-2021-3629P4MEDIUMCVSS 5.9v7.4v7.32022-05-24
CVE-2021-3629 [MEDIUM] CWE-400 CVE-2021-3629: A flaw was found in Undertow. A potential security issue in flow control handling by the browser ove
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
nvd
CVE-2018-14642P4MEDIUMCVSS 5.3v7.1v7.2+1 more2018-09-18
CVE-2018-14642 [MEDIUM] CWE-200 CVE-2018-14642: An information leak vulnerability was found in Undertow. If all headers are not written out in the f
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
nvd
CVE-2018-10862P4MEDIUMCVSS 5.5v7.1.02018-07-27
CVE-2018-10862 [MEDIUM] CWE-22 CVE-2018-10862: WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, all
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
nvd
CVE-2009-0027P4MEDIUMCVSS 5.0v4.2.0v4.3.02009-03-09
CVE-2009-0027 [MEDIUM] CWE-20 CVE-2009-0027: The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.
nvd
CVE-2021-3642P4MEDIUMCVSS 5.3v7.0.02021-08-05
CVE-2021-3642 [MEDIUM] CWE-203 CVE-2021-3642: A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and pr
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
nvd
CVE-2016-4993P4MEDIUMCVSS 6.1≤ 7.0.12016-09-26
CVE-2016-4993 [MEDIUM] CWE-93 CVE-2016-4993: CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v7.2v7.32019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2021-3597P4MEDIUMCVSS 5.9v7.3v7.42022-05-24
CVE-2021-3597 [MEDIUM] CWE-362 CVE-2021-3597: A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circu
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior
nvd