CVE-2018-12022
- EPSS 2.93%
- Published 21.03.2019 16:00:12
- Last modified 21.11.2024 03:44:25
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in ...
CVE-2018-12023
- EPSS 4.9%
- Published 21.03.2019 16:00:12
- Last modified 21.11.2024 03:44:26
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...
CVE-2018-14720
- EPSS 3.41%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:49:40
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- EPSS 9.9%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:49:40
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-14642
- EPSS 0.75%
- Published 18.09.2018 13:29:00
- Last modified 21.11.2024 03:49:29
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain...
CVE-2016-7066
- EPSS 0.03%
- Published 11.09.2018 14:29:00
- Last modified 21.11.2024 02:57:23
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
CVE-2016-7061
- EPSS 0.59%
- Published 10.09.2018 16:29:00
- Last modified 21.11.2024 02:57:22
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive infor...
CVE-2018-1000632
- EPSS 1%
- Published 20.08.2018 19:31:31
- Last modified 21.11.2024 03:40:16
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be explo...
CVE-2018-1336
- EPSS 16.09%
- Published 02.08.2018 14:29:00
- Last modified 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2016-8657
- EPSS 0.06%
- Published 31.07.2018 19:29:00
- Last modified 21.11.2024 02:59:46
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d ...