Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-33544

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after decompression being stored in any location, even leading to file overwrite.
Attacker Value
Unknown

CVE-2019-9827

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
0
Attacker Value
Unknown

CVE-2017-2589

Disclosure Date: July 26, 2018 (last updated November 27, 2024)
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
0
Attacker Value
Unknown

CVE-2017-2617

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
0
Attacker Value
Unknown

CVE-2017-2594

Disclosure Date: May 08, 2018 (last updated November 26, 2024)
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undisclosed information from within hawtio's root.
0
Attacker Value
Unknown

CVE-2014-0121

Disclosure Date: December 29, 2017 (last updated November 26, 2024)
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
0
Attacker Value
Unknown

CVE-2014-0120

Disclosure Date: December 29, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
0
Attacker Value
Unknown

CVE-2017-7556

Disclosure Date: August 17, 2017 (last updated November 26, 2024)
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
0
Attacker Value
Unknown

CVE-2005-4511

Disclosure Date: December 23, 2005 (last updated February 22, 2025)
Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls.
0