CVE-2018-8039
- EPSS 2.77%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:09
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to ma...
CVE-2017-7465
- EPSS 3.68%
- Veröffentlicht 27.06.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transfor...
CVE-2018-1000180
- EPSS 0.24%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. T...
CVE-2016-8656
- EPSS 0.07%
- Veröffentlicht 22.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:46
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
CVE-2018-1067
- EPSS 0.63%
- Veröffentlicht 21.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:06
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization...
CVE-2016-8627
- EPSS 0.8%
- Veröffentlicht 11.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:42
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's bro...
CVE-2018-10237
- EPSS 3.26%
- Veröffentlicht 26.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:04
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray...
CVE-2017-12196
- EPSS 0.21%
- Veröffentlicht 18.04.2018 01:29:01
- Zuletzt bearbeitet 21.11.2024 03:09:01
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the a...
CVE-2018-8088
- EPSS 0.84%
- Veröffentlicht 20.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:14
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1....
CVE-2016-9585
- EPSS 0.18%
- Veröffentlicht 09.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:26
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.