Redhat Jboss Enterprise Web Server vulnerabilities
34 known vulnerabilities affecting redhat/jboss_enterprise_web_server.
Total CVEs
34
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
6
Severity breakdown
CRITICAL7HIGH16MEDIUM10LOW1
Vulnerabilities
Page 2 of 2
CVE-2019-1559P3MEDIUMCVSS 5.9v5.0.02019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2020-25710P3HIGHCVSS 7.5v2.0.02021-05-28
CVE-2020-25710 [HIGH] CWE-617 CVE-2020-25710: A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a mal
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
nvd
CVE-2012-0031P4MEDIUMCVSS 4.6PoCv1.0.02012-01-18
CVE-2012-0031 [MEDIUM] CVE-2012-0031: scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
nvd
CVE-2012-5626P3HIGHCVSS 7.5v1.0.02020-01-23
CVE-2012-5626 [HIGH] CVE-2012-5626: EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss O
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
nvd
CVE-2016-0762P3MEDIUMCVSS 5.9v3.0.02017-08-10
CVE-2016-0762 [MEDIUM] CWE-203 CVE-2016-0762: The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm
nvd
CVE-2015-5183P3HIGHCVSS 7.5v1.0.02017-09-25
CVE-2015-5183 [HIGH] CVE-2015-5183: Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
nvd
CVE-2016-3110P3HIGHCVSS 7.5v2.0.0v2.12016-09-26
CVE-2016-3110 [HIGH] CWE-20 CVE-2016-3110: mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of s
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
nvd
CVE-2016-6794P3MEDIUMCVSS 5.3v3.0.02017-08-10
CVE-2016-6794 [MEDIUM] CVE-2016-6794: When a SecurityManager is configured, a web application's ability to read system properties should b
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to byp
nvd
CVE-2015-5184P4HIGHCVSS 7.5v1.0.02017-09-25
CVE-2015-5184 [HIGH] CVE-2015-5184: Console: CORS headers set to allow all in Red Hat AMQ.
Console: CORS headers set to allow all in Red Hat AMQ.
nvd
CVE-2011-3348P4MEDIUMCVSS 4.3v1.0.02011-09-20
CVE-2011-3348 [MEDIUM] CWE-400 CVE-2011-3348: The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
nvd
CVE-2017-12613P4HIGHCVSS 7.1v3.0.02017-10-24
CVE-2017-12613 [HIGH] CWE-125 CVE-2017-12613: When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value i
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting in program termination, and may rep
nvd
CVE-2013-1976P4MEDIUMCVSS 6.9v1.0.2v2.0.02013-07-09
CVE-2013-1976 [MEDIUM] CWE-59 CVE-2013-1976: The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomca
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-i
nvd
CVE-2014-3655P4MEDIUMCVSS 4.3v1.0.02019-11-13
CVE-2014-3655 [MEDIUM] CWE-352 CVE-2014-3655: JBoss KeyCloak is vulnerable to soft token deletion via CSRF
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
nvd
CVE-2012-2148P4LOWCVSS 3.3v1.0.02019-12-06
CVE-2012-2148 [LOW] CWE-269 CVE-2012-2148: An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores jav
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
nvd
← Previous2 / 2