CVE-2021-40690
- EPSS 0.33%
- Published 19.09.2021 18:15:07
- Last modified 21.11.2024 06:24:34
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...
CVE-2021-33037
- EPSS 3.1%
- Published 12.07.2021 15:15:08
- Last modified 21.11.2024 06:08:10
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specific...
CVE-2021-30468
- EPSS 0.4%
- Published 16.06.2021 12:15:12
- Last modified 21.11.2024 06:03:58
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF vers...
CVE-2020-13931
- EPSS 1.37%
- Published 18.12.2020 00:15:14
- Last modified 21.11.2024 05:02:10
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. ...
CVE-2020-11969
- EPSS 1.11%
- Published 15.06.2020 20:15:11
- Last modified 21.11.2024 04:59:00
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache...
CVE-2019-17569
- EPSS 6.16%
- Published 24.02.2020 22:15:11
- Last modified 21.11.2024 04:32:33
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of H...
CVE-2019-17359
- EPSS 7.63%
- Published 08.10.2019 14:15:10
- Last modified 12.05.2025 17:37:16
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVE-2019-13990
- EPSS 10.42%
- Published 26.07.2019 19:15:11
- Last modified 21.11.2024 04:25:50
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
CVE-2018-8031
- EPSS 2.26%
- Published 23.07.2018 22:29:00
- Last modified 21.11.2024 04:13:07
The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles...
CVE-2016-0779
- EPSS 9.01%
- Published 11.04.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.