CVE-2021-3629
- EPSS 0.11%
- Veröffentlicht 24.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:01
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw af...
CVE-2021-3717
- EPSS 0.04%
- Veröffentlicht 24.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:14
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, inte...
CVE-2022-0866
- EPSS 0.27%
- Veröffentlicht 10.05.2022 21:15:08
- Zuletzt bearbeitet 06.11.2025 11:33:54
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRu...
CVE-2022-0853
- EPSS 1.7%
- Veröffentlicht 11.03.2022 18:15:25
- Zuletzt bearbeitet 21.11.2024 06:39:31
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
CVE-2021-20318
- EPSS 2.13%
- Veröffentlicht 23.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:22
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
CVE-2021-4104
- EPSS 72.2%
- Veröffentlicht 14.12.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 06:36:54
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...
CVE-2021-32029
- EPSS 0.19%
- Veröffentlicht 08.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:44
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
CVE-2021-3642
- EPSS 0.27%
- Veröffentlicht 05.08.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:03
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
CVE-2020-14340
- EPSS 0.31%
- Veröffentlicht 02.06.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 05:03:02
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 t...
CVE-2020-14317
- EPSS 0.03%
- Veröffentlicht 02.06.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:02:59
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file i...