Redhat

Jboss Enterprise Soa Platform

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...

  • EPSS 0.84%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authe...

  • EPSS 1.22%
  • Veröffentlicht 27.07.2011 02:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enter...

  • EPSS 1.2%
  • Veröffentlicht 27.07.2011 02:42:27
  • Zuletzt bearbeitet 11.04.2025 00:51:21

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly re...

  • EPSS 2.42%
  • Veröffentlicht 30.12.2010 21:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote ...

  • EPSS 0.25%
  • Veröffentlicht 10.08.2010 12:23:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a serv...

  • EPSS 0.11%
  • Veröffentlicht 10.08.2010 12:23:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_proxy_security quickstart, (3) the web-console application, (4) the http-invoker application, (5) the g...