Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-10734

Disclosure Date: February 11, 2021 (last updated November 28, 2024)
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
Attacker Value
Unknown

CVE-2020-1717

Disclosure Date: February 11, 2021 (last updated November 28, 2024)
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
Attacker Value
Unknown

CVE-2020-25689

Disclosure Date: November 02, 2020 (last updated November 28, 2024)
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-14299

Disclosure Date: October 16, 2020 (last updated November 28, 2024)
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-25644

Disclosure Date: October 06, 2020 (last updated February 22, 2024)
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-10758

Disclosure Date: September 16, 2020 (last updated November 28, 2024)
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
Attacker Value
Unknown

CVE-2020-1710

Disclosure Date: September 16, 2020 (last updated November 28, 2024)
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Attacker Value
Unknown

CVE-2020-14307

Disclosure Date: July 24, 2020 (last updated November 28, 2024)
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
Attacker Value
Unknown

CVE-2020-14297

Disclosure Date: July 24, 2020 (last updated December 30, 2023)
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Attacker Value
Unknown

CVE-2019-14900

Disclosure Date: July 06, 2020 (last updated November 08, 2023)
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.