CVE-2013-1862
- EPSS 24.89%
- Veröffentlicht 10.06.2013 17:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containi...
CVE-2012-5629
- EPSS 2.34%
- Veröffentlicht 12.03.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authenticati...
CVE-2011-4575
- EPSS 1.79%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbi...
CVE-2012-0034
- EPSS 0.4%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows l...
CVE-2012-0874
- EPSS 14%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentica...
- EPSS 2.69%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via ...
CVE-2012-3370
- EPSS 1.86%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a s...
CVE-2012-5478
- EPSS 2.18%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated ...
CVE-2013-0218
- EPSS 0.37%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password a...
CVE-2012-4549
- EPSS 1.31%
- Veröffentlicht 05.01.2013 00:55:02
- Zuletzt bearbeitet 16.06.2026 23:45:18
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Jav...