Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.8%
  • Veröffentlicht 16.12.2015 21:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecif...

  • EPSS 2.98%
  • Veröffentlicht 27.10.2015 16:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.

  • EPSS 1.14%
  • Veröffentlicht 27.10.2015 16:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentica...

  • EPSS 1.71%
  • Veröffentlicht 27.10.2015 16:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks vi...

  • EPSS 0.37%
  • Veröffentlicht 21.04.2015 17:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitiv...

  • EPSS 0.8%
  • Veröffentlicht 20.02.2015 16:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying...

  • EPSS 1.24%
  • Veröffentlicht 13.02.2015 15:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote a...

  • EPSS 1.26%
  • Veröffentlicht 13.02.2015 15:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise r...

  • EPSS 1.74%
  • Veröffentlicht 13.02.2015 15:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote ...

  • EPSS 0.35%
  • Veröffentlicht 17.11.2014 22:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.