CVE-2016-4993
- EPSS 1.13%
- Veröffentlicht 26.09.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting a...
CVE-2016-3110
- EPSS 3.22%
- Veröffentlicht 26.09.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
CVE-2016-2183
- EPSS 40.02%
- Veröffentlicht 01.09.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-2141
- EPSS 1.55%
- Veröffentlicht 30.06.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages wi...
CVE-2015-5304
- EPSS 1.29%
- Veröffentlicht 16.12.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecif...
- EPSS 1.52%
- Veröffentlicht 27.10.2015 16:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
CVE-2015-5188
- EPSS 0.33%
- Veröffentlicht 27.10.2015 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentica...
CVE-2015-5178
- EPSS 0.51%
- Veröffentlicht 27.10.2015 16:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks vi...
CVE-2014-3586
- EPSS 0.05%
- Veröffentlicht 21.04.2015 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitiv...
CVE-2014-0005
- EPSS 0.21%
- Veröffentlicht 20.02.2015 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying...