CVE-2018-1336
- EPSS 18.55%
- Veröffentlicht 02.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2016-8657
- EPSS 0.06%
- Veröffentlicht 31.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:46
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d ...
CVE-2017-12165
- EPSS 1.1%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:57
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
CVE-2017-2595
- EPSS 1.17%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:47
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
CVE-2017-2670
- EPSS 5.97%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
CVE-2017-2666
- EPSS 2.22%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject...
CVE-2018-10862
- EPSS 0.33%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:10
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
CVE-2017-7464
- EPSS 0.56%
- Veröffentlicht 27.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for pars...
CVE-2017-12167
- EPSS 0.05%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:58
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to...
CVE-2017-2582
- EPSS 0.66%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:46
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at...