CVE-2016-5018
- EPSS 0.94%
- Veröffentlicht 10.08.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applica...
CVE-2017-9788
- EPSS 49.5%
- Veröffentlicht 13.07.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2016-3690
- EPSS 1.77%
- Veröffentlicht 08.06.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
CVE-2017-7504
- EPSS 90.28%
- Veröffentlicht 19.05.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows r...
CVE-2017-7503
- EPSS 0.66%
- Veröffentlicht 18.05.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
CVE-2016-7065
- EPSS 12.1%
- Veröffentlicht 13.10.2016 14:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
CVE-2016-7046
- EPSS 4.06%
- Veröffentlicht 03.10.2016 21:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
CVE-2016-4978
- EPSS 1.36%
- Veröffentlicht 27.09.2016 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages t...
CVE-2016-5406
- EPSS 1.5%
- Veröffentlicht 26.09.2016 14:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
CVE-2016-4993
- EPSS 1.48%
- Veröffentlicht 26.09.2016 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting a...