CVE-2016-8653
- EPSS 0.35%
- Published 01.08.2018 14:29:00
- Last modified 21.11.2024 02:59:46
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
CVE-2016-8648
- EPSS 0.54%
- Published 01.08.2018 14:29:00
- Last modified 21.11.2024 02:59:45
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the J...
- EPSS 71.46%
- Published 09.11.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x...
CVE-2015-5183
- EPSS 0.4%
- Published 25.09.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
CVE-2015-5181
- EPSS 0.17%
- Published 25.09.2017 21:29:00
- Last modified 20.04.2025 01:37:25
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
CVE-2014-0085
- EPSS 0.14%
- Published 17.04.2014 14:55:06
- Last modified 12.04.2025 10:46:40
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the so...
CVE-2013-4372
- EPSS 0.42%
- Published 30.09.2013 21:55:07
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the ...