Show filters
273 Total Results
Displaying 101-110 of 273
Sort by:
Attacker Value
Unknown

CVE-2014-0169

Disclosure Date: January 02, 2020 (last updated February 21, 2025)
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.
Attacker Value
Unknown

CVE-2012-2312

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Attacker Value
Unknown

CVE-2013-6495

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
JBossWeb Bayeux has reflected XSS
Attacker Value
Unknown

CVE-2019-10174

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Attacker Value
Unknown

CVE-2019-10172

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
Attacker Value
Unknown

CVE-2019-14379

Disclosure Date: November 12, 2019 (last updated November 08, 2023)
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Attacker Value
Unknown

CVE-2019-0210

Disclosure Date: October 29, 2019 (last updated November 08, 2023)
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Attacker Value
Unknown

CVE-2019-0205

Disclosure Date: October 29, 2019 (last updated November 08, 2023)
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Attacker Value
Unknown

CVE-2019-14838

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server