Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
High

CVE-2016-2183

Disclosure Date: September 01, 2016 (last updated November 25, 2024)
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Attacker Value
Unknown

CVE-2012-5626

Disclosure Date: January 23, 2020 (last updated November 28, 2024)
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
Attacker Value
Unknown

CVE-2014-3701

Disclosure Date: December 15, 2019 (last updated November 27, 2024)
eDeploy has tmp file race condition flaws
Attacker Value
Unknown

CVE-2014-3699

Disclosure Date: December 15, 2019 (last updated November 27, 2024)
eDeploy has RCE via cPickle deserialization of untrusted data
Attacker Value
Unknown

CVE-2012-2148

Disclosure Date: December 06, 2019 (last updated November 27, 2024)
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
Attacker Value
Unknown

CVE-2014-3700

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Attacker Value
Unknown

CVE-2014-3655

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
Attacker Value
Unknown

CVE-2011-3923

Disclosure Date: November 01, 2019 (last updated November 08, 2023)
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Attacker Value
Unknown

CVE-2015-5184

Disclosure Date: September 25, 2017 (last updated November 08, 2023)
Console: CORS headers set to allow all in Red Hat AMQ.
Attacker Value
Unknown

CVE-2015-5183

Disclosure Date: September 25, 2017 (last updated November 08, 2023)
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.