CVE-2020-17516
- EPSS 0.85%
- Veröffentlicht 03.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:16
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a maliciou...
CVE-2020-13946
- EPSS 0.29%
- Veröffentlicht 01.09.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:12
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-...
CVE-2019-2684
- EPSS 1.26%
- Veröffentlicht 23.04.2019 19:32:55
- Zuletzt bearbeitet 21.11.2024 04:41:21
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthen...
CVE-2018-8016
- EPSS 0.61%
- Veröffentlicht 28.06.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:06
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-...
CVE-2016-4970
- EPSS 8.23%
- Veröffentlicht 13.04.2017 14:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
- EPSS 93.49%
- Veröffentlicht 21.04.2016 11:00:21
- Zuletzt bearbeitet 22.04.2026 13:41:41
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CVE-2015-0225
- EPSS 0.67%
- Veröffentlicht 03.04.2015 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via a...