Show filters
273 Total Results
Displaying 141-150 of 273
Sort by:
Attacker Value
Unknown

CVE-2016-7066

Disclosure Date: September 11, 2018 (last updated November 08, 2023)
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
0
Attacker Value
Unknown

CVE-2016-7061

Disclosure Date: September 10, 2018 (last updated November 08, 2023)
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
0
Attacker Value
Unknown

CVE-2018-1000632

Disclosure Date: August 20, 2018 (last updated November 08, 2023)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Attacker Value
Unknown

CVE-2018-1336

Disclosure Date: August 02, 2018 (last updated December 09, 2023)
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Attacker Value
Unknown

CVE-2016-8657

Disclosure Date: July 31, 2018 (last updated November 27, 2024)
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privileges when jboss service is started, stopped, or restarted.
0
Attacker Value
Unknown

CVE-2017-2595

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
0
Attacker Value
Unknown

CVE-2017-12165

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
0
Attacker Value
Unknown

CVE-2017-2670

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
0
Attacker Value
Unknown

CVE-2017-2666

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
0
Attacker Value
Unknown

CVE-2018-10862

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
0