Show filters
273 Total Results
Displaying 191-200 of 273
Sort by:
Attacker Value
Unknown

CVE-2017-7503

Disclosure Date: May 18, 2017 (last updated November 26, 2024)
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
0
Attacker Value
Unknown

CVE-2017-7525

Disclosure Date: April 11, 2017 (last updated December 06, 2023)
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
Attacker Value
Unknown

CVE-2016-7065

Disclosure Date: October 13, 2016 (last updated November 25, 2024)
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
0
Attacker Value
Unknown

CVE-2016-7046

Disclosure Date: October 03, 2016 (last updated November 25, 2024)
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
0
Attacker Value
Unknown

CVE-2016-4978

Disclosure Date: September 27, 2016 (last updated November 25, 2024)
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.
Attacker Value
Unknown

CVE-2016-3110

Disclosure Date: September 26, 2016 (last updated November 25, 2024)
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
0
Attacker Value
Unknown

CVE-2016-5406

Disclosure Date: September 26, 2016 (last updated November 25, 2024)
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
0
Attacker Value
Unknown

CVE-2016-4993

Disclosure Date: September 26, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-2141

Disclosure Date: June 30, 2016 (last updated November 08, 2023)
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Attacker Value
Unknown

CVE-2015-5304

Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.
0