Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 27.89%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so...

  • EPSS 8.11%
  • Veröffentlicht 29.07.2019 12:15:16
  • Zuletzt bearbeitet 08.10.2026 21:17:12

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

  • EPSS 3.48%
  • Veröffentlicht 25.07.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:36

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

  • EPSS 0.7%
  • Veröffentlicht 12.06.2019 14:29:04
  • Zuletzt bearbeitet 21.11.2024 04:42:46

It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unau...

  • EPSS 0.93%
  • Veröffentlicht 12.06.2019 14:29:04
  • Zuletzt bearbeitet 21.11.2024 04:42:46

It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further a...

  • EPSS 0.19%
  • Veröffentlicht 03.05.2019 20:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:34

A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss...

  • EPSS 1.51%
  • Veröffentlicht 03.05.2019 20:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:48

It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could all...

  • EPSS 0.95%
  • Veröffentlicht 27.03.2019 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:20

A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

  • EPSS 7.35%
  • Veröffentlicht 21.03.2019 16:00:12
  • Zuletzt bearbeitet 08.10.2026 21:17:07

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in ...

  • EPSS 8.94%
  • Veröffentlicht 21.03.2019 16:00:12
  • Zuletzt bearbeitet 21.11.2024 03:44:26

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...