Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 91.9%
  • Veröffentlicht 14.10.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...

Warnung
  • EPSS 90.71%
  • Veröffentlicht 04.10.2017 21:01:00
  • Zuletzt bearbeitet 07.10.2026 17:58:24

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus al...

Warnung Exploit
  • EPSS 99.99%
  • Veröffentlicht 04.10.2017 01:29:02
  • Zuletzt bearbeitet 25.08.2026 16:28:27

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 19.09.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

  • EPSS 1.51%
  • Veröffentlicht 13.09.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.

  • EPSS 2.26%
  • Veröffentlicht 22.08.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

  • EPSS 8.32%
  • Veröffentlicht 11.08.2017 02:29:00
  • Zuletzt bearbeitet 08.10.2026 22:16:38

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for t...

Exploit
  • EPSS 10.3%
  • Veröffentlicht 10.08.2017 16:29:00
  • Zuletzt bearbeitet 08.10.2026 22:16:38

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applica...

  • EPSS 56.77%
  • Veröffentlicht 13.07.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...

  • EPSS 5.24%
  • Veröffentlicht 08.06.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.