CVE-2016-8648
- EPSS 0.54%
- Veröffentlicht 01.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:45
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the J...
CVE-2016-8653
- EPSS 0.35%
- Veröffentlicht 01.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:46
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
- EPSS 0.18%
- Veröffentlicht 26.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:47
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that pro...
CVE-2017-12196
- EPSS 0.23%
- Veröffentlicht 18.04.2018 01:29:01
- Zuletzt bearbeitet 21.11.2024 03:09:01
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the a...
CVE-2014-0121
- EPSS 1.53%
- Veröffentlicht 29.12.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
CVE-2014-0120
- EPSS 0.15%
- Veröffentlicht 29.12.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
- EPSS 71.46%
- Veröffentlicht 09.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x...
- EPSS 0.19%
- Veröffentlicht 08.07.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
CVE-2013-7398
- EPSS 1.23%
- Veröffentlicht 24.06.2015 16:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof ...
CVE-2013-7397
- EPSS 1.06%
- Veröffentlicht 24.06.2015 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presen...