Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.67%
  • Veröffentlicht 30.01.2025 15:15:18
  • Zuletzt bearbeitet 18.09.2026 00:16:51

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resum...

  • EPSS 1.12%
  • Veröffentlicht 17.11.2024 11:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary addit...

  • EPSS 0.47%
  • Veröffentlicht 07.11.2024 10:15:04
  • Zuletzt bearbeitet 24.06.2025 13:07:42

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an inva...

  • EPSS 0.64%
  • Veröffentlicht 22.10.2024 14:15:14
  • Zuletzt bearbeitet 19.08.2026 01:16:52

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior aga...

  • EPSS 2.64%
  • Veröffentlicht 21.08.2024 14:15:09
  • Zuletzt bearbeitet 08.10.2026 11:16:41

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection....

Exploit
  • EPSS 0.79%
  • Veröffentlicht 25.04.2024 17:15:47
  • Zuletzt bearbeitet 07.10.2026 23:16:57

A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

  • EPSS 0.78%
  • Veröffentlicht 09.04.2024 07:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result ...

  • EPSS 3.48%
  • Veröffentlicht 22.03.2024 19:15:07
  • Zuletzt bearbeitet 14.09.2026 20:16:36

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

  • EPSS 4.57%
  • Veröffentlicht 19.02.2024 22:15:48
  • Zuletzt bearbeitet 07.10.2026 22:17:01

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immedia...

  • EPSS 0.72%
  • Veröffentlicht 06.02.2024 09:15:52
  • Zuletzt bearbeitet 21.11.2024 08:35:18

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the serve...