Redhat

Jboss Enterprise Application Platform

254 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.29%
  • Veröffentlicht 06.05.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:55:52

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping...

  • EPSS 0.66%
  • Veröffentlicht 04.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:15

A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being han...

  • EPSS 1.58%
  • Veröffentlicht 21.04.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:19

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the ...

  • EPSS 1.1%
  • Veröffentlicht 16.03.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:36

A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version...

  • EPSS 1.76%
  • Veröffentlicht 11.03.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 01:28:23

The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.

  • EPSS 5.62%
  • Veröffentlicht 02.03.2020 17:15:17
  • Zuletzt bearbeitet 08.10.2026 21:17:14

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to ex...

Exploit
  • EPSS 8.91%
  • Veröffentlicht 29.01.2020 21:15:11
  • Zuletzt bearbeitet 08.10.2026 22:16:53

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

Exploit
  • EPSS 13.47%
  • Veröffentlicht 29.01.2020 21:15:11
  • Zuletzt bearbeitet 08.10.2026 22:16:53

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Exploit
  • EPSS 3.62%
  • Veröffentlicht 27.01.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:53

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869...

  • EPSS 0.74%
  • Veröffentlicht 23.01.2020 22:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:36

A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw ca...