CVE-2009-2405
- EPSS 2.53%
- Veröffentlicht 15.12.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:22
Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remo...
- EPSS 1.81%
- Veröffentlicht 09.03.2009 21:30:00
- Zuletzt bearbeitet 16.06.2026 23:04:06
The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service e...
CVE-2008-3519
- EPSS 1.62%
- Veröffentlicht 23.09.2008 15:24:43
- Zuletzt bearbeitet 16.06.2026 22:55:58
The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property...
CVE-2008-0455
- EPSS 64.77%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:40
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated use...