CVE-2017-2670
- EPSS 3.66%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
CVE-2017-2666
- EPSS 2.71%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject...
CVE-2018-10862
- EPSS 1.26%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:10
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
CVE-2017-7464
- EPSS 1.91%
- Veröffentlicht 27.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for pars...
CVE-2017-12167
- EPSS 0.38%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:58
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to...
CVE-2017-2582
- EPSS 2.46%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:46
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at...
CVE-2018-8039
- EPSS 10.35%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:09
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to ma...
CVE-2017-7465
- EPSS 2.98%
- Veröffentlicht 27.06.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transfor...
CVE-2018-1000180
- EPSS 3.58%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. T...
CVE-2016-8656
- EPSS 0.37%
- Veröffentlicht 22.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:46
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.