Show filters
273 Total Results
Displaying 201-210 of 273
Sort by:
Attacker Value
Unknown
CVE-2015-5220
Disclosure Date: October 27, 2015 (last updated October 05, 2023)
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
0
Attacker Value
Unknown
CVE-2015-5188
Disclosure Date: October 27, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.
0
Attacker Value
Unknown
CVE-2015-5178
Disclosure Date: October 27, 2015 (last updated October 05, 2023)
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
0
Attacker Value
Unknown
CVE-2014-3586
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-0005
Disclosure Date: February 20, 2015 (last updated October 05, 2023)
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
0
Attacker Value
Unknown
CVE-2014-7849
Disclosure Date: February 13, 2015 (last updated October 05, 2023)
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
0
Attacker Value
Unknown
CVE-2014-7853
Disclosure Date: February 13, 2015 (last updated October 05, 2023)
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
0
Attacker Value
Unknown
CVE-2014-7827
Disclosure Date: February 13, 2015 (last updated October 05, 2023)
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
0
Attacker Value
Unknown
CVE-2014-0059
Disclosure Date: November 17, 2014 (last updated October 05, 2023)
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.
0
Attacker Value
Unknown
CVE-2014-3490
Disclosure Date: August 19, 2014 (last updated October 05, 2023)
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
0