Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 28.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share clas...

  • EPSS 2.67%
  • Veröffentlicht 01.10.2013 17:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of s...

  • EPSS 1.61%
  • Veröffentlicht 28.09.2013 19:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

  • EPSS 0.24%
  • Veröffentlicht 28.09.2013 19:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

  • EPSS 6.32%
  • Veröffentlicht 19.08.2013 23:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers...

  • EPSS 2.47%
  • Veröffentlicht 16.08.2013 16:55:46
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.

  • EPSS 2.44%
  • Veröffentlicht 16.08.2013 16:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.

  • EPSS 2.66%
  • Veröffentlicht 29.07.2013 13:59:54
  • Zuletzt bearbeitet 29.04.2026 01:13:23

wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communicat...

  • EPSS 12.66%
  • Veröffentlicht 23.07.2013 11:03:11
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0...

Exploit
  • EPSS 29.48%
  • Veröffentlicht 10.07.2013 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for han...