Lucene search

K

JBoss Security Vulnerabilities

cve
cve

CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege...

7.8CVSS

7.4AI Score

0.0004EPSS

2018-05-22 05:29 PM
56
cve
cve

CVE-2011-3606

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM....

5.4CVSS

5.4AI Score

0.001EPSS

2019-11-26 02:15 AM
59
cve
cve

CVE-2011-3609

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin...

6.5CVSS

6.4AI Score

0.002EPSS

2019-11-26 03:15 AM
58
cve
cve

CVE-2012-2312

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated...

7.8CVSS

7.4AI Score

0.0004EPSS

2019-12-18 06:15 PM
27
cve
cve

CVE-2014-3652

JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect...

6.1CVSS

6.2AI Score

0.001EPSS

2019-12-15 10:15 PM
70
cve
cve

CVE-2014-3656

JBoss KeyCloak: XSS in...

6.1CVSS

5.9AI Score

0.001EPSS

2019-12-10 02:15 PM
33
cve
cve

CVE-2014-3655

JBoss KeyCloak is vulnerable to soft token deletion via...

4.3CVSS

4.6AI Score

0.001EPSS

2019-11-13 04:15 PM
42
cve
cve

CVE-2010-3857

JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID...

6.1CVSS

6AI Score

0.001EPSS

2019-11-12 11:15 PM
46
cve
cve

CVE-2014-3649

JBoss AeroGear has reflected XSS via the password...

6.1CVSS

6.1AI Score

0.001EPSS

2019-11-04 03:15 PM
17
cve
cve

CVE-2018-1041

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite...

7.5CVSS

7AI Score

0.027EPSS

2018-02-15 05:29 PM
59
cve
cve

CVE-2016-2094

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout...

7.5CVSS

7.2AI Score

0.023EPSS

2016-05-06 05:59 PM
35
cve
cve

CVE-2014-0170

Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE)...

6.9AI Score

0.004EPSS

2014-09-30 02:55 PM
24
cve
cve

CVE-2012-3428

The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource.....

6.6AI Score

0.008EPSS

2012-12-20 12:02 PM
25
cve
cve

CVE-2008-3273

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query...

5.8AI Score

0.005EPSS

2008-08-10 08:41 PM
59
cve
cve

CVE-2007-6433

The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order...

7.4AI Score

0.016EPSS

2007-12-18 08:46 PM
33
cve
cve

CVE-2007-1354

The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by....

6.8AI Score

0.004EPSS

2007-07-27 09:30 PM
28
cve
cve

CVE-2007-1157

Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than...

6.6AI Score

0.079EPSS

2007-03-02 09:18 PM
33
cve
cve

CVE-2007-1036

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct...

6.8AI Score

0.966EPSS

2007-02-21 11:28 AM
103
In Wild
cve
cve

CVE-2006-5750

Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the console...

6.7AI Score

0.432EPSS

2006-11-27 08:07 PM
30
cve
cve

CVE-2005-4709

The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an.....

7.6AI Score

0.006EPSS

2006-02-02 11:00 AM
16
cve
cve

CVE-2005-2158

A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by...

7.4AI Score

0.109EPSS

2005-07-06 04:00 AM
21
cve
cve

CVE-2005-2006

JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the...

6AI Score

0.039EPSS

2005-06-20 04:00 AM
31
cve
cve

CVE-2003-0845

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1,.....

7.9AI Score

0.109EPSS

2003-11-17 05:00 AM
41