CVE-2014-3490
- EPSS 4.57%
- Veröffentlicht 19.08.2014 18:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows...
CVE-2014-3464
- EPSS 1.09%
- Veröffentlicht 19.08.2014 18:55:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated use...
CVE-2014-3472
- EPSS 1.68%
- Veröffentlicht 19.08.2014 18:55:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass a...
CVE-2014-3518
- EPSS 2.61%
- Veröffentlicht 22.07.2014 20:55:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 sp...
CVE-2014-3530
- EPSS 3.86%
- Veröffentlicht 22.07.2014 20:55:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary c...
CVE-2014-0118
- EPSS 37.16%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 06.05.2026 22:30:45
The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted req...
CVE-2014-0226
- EPSS 85.74%
- Veröffentlicht 20.07.2014 11:12:48
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a cr...
CVE-2014-0034
- EPSS 7.41%
- Veröffentlicht 07.07.2014 14:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
CVE-2014-0035
- EPSS 7.05%
- Veröffentlicht 07.07.2014 14:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers...
CVE-2014-0248
- EPSS 3.51%
- Veröffentlicht 07.07.2014 14:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted aut...