CVE-2017-7504
- EPSS 29.32%
- Veröffentlicht 19.05.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows r...
CVE-2017-7503
- EPSS 2.01%
- Veröffentlicht 18.05.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
CVE-2016-7065
- EPSS 12.47%
- Veröffentlicht 13.10.2016 14:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.
CVE-2016-7046
- EPSS 2.48%
- Veröffentlicht 03.10.2016 21:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
CVE-2016-4978
- EPSS 6.88%
- Veröffentlicht 27.09.2016 15:59:01
- Zuletzt bearbeitet 15.06.2026 13:03:40
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages t...
CVE-2016-5406
- EPSS 2.9%
- Veröffentlicht 26.09.2016 14:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
CVE-2016-4993
- EPSS 2.56%
- Veröffentlicht 26.09.2016 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting a...
CVE-2016-3110
- EPSS 3.64%
- Veröffentlicht 26.09.2016 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
- EPSS 95.71%
- Veröffentlicht 01.09.2016 00:59:00
- Zuletzt bearbeitet 29.05.2026 21:16:27
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-2141
- EPSS 4.7%
- Veröffentlicht 30.06.2016 16:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages wi...