Redhat Jboss Enterprise Brms Platform vulnerabilities
23 known vulnerabilities affecting redhat/jboss_enterprise_brms_platform.
Total CVEs
23
CISA KEV
0
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH4MEDIUM14LOW3
Vulnerabilities
Page 2 of 2
CVE-2012-2377P4LOWCVSS 3.3≤ 5.2.02012-11-23
CVE-2012-2377 [LOW] CWE-287 CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
nvd
CVE-2014-0005P4LOWCVSS 3.6≤ 6.0.32015-02-20
CVE-2014-0005 [LOW] CWE-264 CVE-2014-0005: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JB
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
nvd
CVE-2012-0034P4LOWCVSS 2.1≤ 5.3.02013-02-05
CVE-2012-0034 [LOW] CWE-255 CVE-2012-0034: The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.
nvd
← Previous2 / 2