Show filters
84 Total Results
Displaying 21-30 of 84
Sort by:
Attacker Value
Unknown

CVE-2020-25689

Disclosure Date: November 02, 2020 (last updated November 28, 2024)
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-14299

Disclosure Date: October 16, 2020 (last updated November 28, 2024)
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-25644

Disclosure Date: October 06, 2020 (last updated February 22, 2024)
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-1710

Disclosure Date: September 16, 2020 (last updated November 28, 2024)
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Attacker Value
Unknown

CVE-2020-14307

Disclosure Date: July 24, 2020 (last updated November 28, 2024)
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
Attacker Value
Unknown

CVE-2020-14297

Disclosure Date: July 24, 2020 (last updated December 30, 2023)
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Attacker Value
Unknown

CVE-2019-14900

Disclosure Date: July 06, 2020 (last updated November 08, 2023)
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Attacker Value
Unknown

CVE-2020-10693

Disclosure Date: May 06, 2020 (last updated November 08, 2023)
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Attacker Value
Unknown

CVE-2020-1732

Disclosure Date: May 04, 2020 (last updated November 08, 2023)
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
Attacker Value
Unknown

CVE-2020-1757

Disclosure Date: April 21, 2020 (last updated November 27, 2024)
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.