Show filters
73 Total Results
Displaying 61-70 of 73
Sort by:
Attacker Value
Unknown
CVE-2016-8648
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
0
Attacker Value
Unknown
CVE-2017-2589
Disclosure Date: July 26, 2018 (last updated November 27, 2024)
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
0
Attacker Value
Unknown
CVE-2017-12196
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
0
Attacker Value
Unknown
CVE-2014-0121
Disclosure Date: December 29, 2017 (last updated November 26, 2024)
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
0
Attacker Value
Unknown
CVE-2014-0120
Disclosure Date: December 29, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
0
Attacker Value
Unknown
CVE-2014-8175
Disclosure Date: July 08, 2015 (last updated October 05, 2023)
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
0
Attacker Value
Unknown
CVE-2013-7398
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2013-7397
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.
0
Attacker Value
Unknown
CVE-2014-5075
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown
CVE-2013-6469
Disclosure Date: April 22, 2014 (last updated November 08, 2023)
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
0