Redhat Jboss Middleware vulnerabilities

6 known vulnerabilities affecting redhat/jboss_middleware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-4065MEDIUMCVSS 5.5v12023-09-27
CVE-2023-4065 [MEDIUM] CWE-117 CVE-2023-4065: A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQAr A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
nvd
CVE-2023-4066MEDIUMCVSS 5.5v12023-09-27
CVE-2023-4066 [MEDIUM] CWE-313 CVE-2023-4066: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-proper A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
nvd
CVE-2023-4853HIGHCVSS 8.1v12023-09-20
CVE-2023-4853 [HIGH] CWE-148 CVE-2023-4853: A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permut A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
nvd
CVE-2018-1304MEDIUMCVSS 5.9v12018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2017-7957HIGHCVSS 7.5v12017-04-29
CVE-2017-7957 [HIGH] CWE-20 CVE-2017-7957: XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to creat XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
nvd
CVE-2016-3674HIGHCVSS 7.5v12016-05-17
CVE-2016-3674 [HIGH] CWE-200 CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDr Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
nvd