Redhat

Jboss Enterprise Application Platform

247 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated ...

  • EPSS 0.05%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password a...

  • EPSS 0.13%
  • Veröffentlicht 05.01.2013 00:55:02
  • Zuletzt bearbeitet 14.05.2026 23:16:32

A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Jav...

  • EPSS 0.2%
  • Veröffentlicht 05.01.2013 00:55:02
  • Zuletzt bearbeitet 14.05.2026 23:16:34

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract...

  • EPSS 0.82%
  • Veröffentlicht 23.11.2012 20:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm...

  • EPSS 0.72%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...

  • EPSS 2.42%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2....

  • EPSS 0.33%
  • Veröffentlicht 22.10.2012 23:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restr...

  • EPSS 0.07%
  • Veröffentlicht 13.08.2012 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.

  • EPSS 0.56%
  • Veröffentlicht 27.01.2012 15:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is...