CVE-2012-3427
- EPSS 0.05%
- Veröffentlicht 02.02.2014 20:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading fi...
CVE-2013-2185
- EPSS 5.29%
- Veröffentlicht 19.01.2014 18:02:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a fi...
CVE-2013-2133
- EPSS 0.33%
- Veröffentlicht 06.12.2013 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated...
CVE-2012-4529
- EPSS 0.56%
- Veröffentlicht 28.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain t...
CVE-2012-4572
- EPSS 0.06%
- Veröffentlicht 28.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share clas...
- EPSS 1.27%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of s...
CVE-2013-4112
- EPSS 0.62%
- Veröffentlicht 28.09.2013 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
CVE-2013-1921
- EPSS 0.05%
- Veröffentlicht 28.09.2013 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
CVE-2012-5575
- EPSS 8.85%
- Veröffentlicht 19.08.2013 23:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers...
CVE-2013-4213
- EPSS 0.59%
- Veröffentlicht 16.08.2013 16:55:46
- Zuletzt bearbeitet 11.04.2025 00:51:21
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.