Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.13%
  • Veröffentlicht 30.12.2010 21:00:02
  • Zuletzt bearbeitet 16.06.2026 23:24:28

The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 t...

  • EPSS 3.02%
  • Veröffentlicht 30.12.2010 21:00:01
  • Zuletzt bearbeitet 16.06.2026 23:23:22

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote ...

  • EPSS 2.61%
  • Veröffentlicht 30.12.2010 21:00:01
  • Zuletzt bearbeitet 16.06.2026 23:23:42

The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 t...

  • EPSS 0.87%
  • Veröffentlicht 30.12.2010 21:00:01
  • Zuletzt bearbeitet 16.06.2026 23:23:44

Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests tha...

Warnung
  • EPSS 83.4%
  • Veröffentlicht 05.08.2010 13:23:09
  • Zuletzt bearbeitet 16.06.2026 23:19:29

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a craf...

Warnung Exploit
  • EPSS 79.42%
  • Veröffentlicht 28.04.2010 22:30:00
  • Zuletzt bearbeitet 02.10.2026 14:55:30

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attack...

Warnung Exploit
  • EPSS 62.31%
  • Veröffentlicht 28.04.2010 22:30:00
  • Zuletzt bearbeitet 02.10.2026 14:55:25

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote atta...

  • EPSS 53.73%
  • Veröffentlicht 28.04.2010 22:30:00
  • Zuletzt bearbeitet 16.06.2026 23:18:22

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demon...

  • EPSS 0.38%
  • Veröffentlicht 15.12.2009 18:30:01
  • Zuletzt bearbeitet 16.06.2026 23:11:50

Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain s...

  • EPSS 2.33%
  • Veröffentlicht 15.12.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:07:09

Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTM...