Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.03%
  • Veröffentlicht 07.07.2014 14:55:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML Ex...

Exploit
  • EPSS 95.33%
  • Veröffentlicht 05.06.2014 21:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL...

  • EPSS 2.1%
  • Veröffentlicht 03.04.2014 16:15:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission an...

  • EPSS 0.35%
  • Veröffentlicht 26.02.2014 15:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.

  • EPSS 0.35%
  • Veröffentlicht 14.02.2014 15:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to ...

  • EPSS 2.17%
  • Veröffentlicht 10.02.2014 23:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via...

  • EPSS 0.35%
  • Veröffentlicht 02.02.2014 20:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading fi...

  • EPSS 7.2%
  • Veröffentlicht 19.01.2014 18:02:57
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a fi...

  • EPSS 1.81%
  • Veröffentlicht 06.12.2013 17:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated...

  • EPSS 1.98%
  • Veröffentlicht 28.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain t...