Apache

Openmeetings

25 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.98%
  • Published 08.01.2025 09:15:07
  • Last modified 15.01.2025 15:50:39

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA th...

  • EPSS 0.07%
  • Published 12.05.2023 08:15:08
  • Last modified 21.11.2024 07:56:45

An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

  • EPSS 0.12%
  • Published 12.05.2023 08:15:08
  • Last modified 21.11.2024 07:56:25

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0

  • EPSS 0.29%
  • Published 12.05.2023 08:15:08
  • Last modified 21.11.2024 07:56:15

Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

  • EPSS 0.16%
  • Published 28.03.2023 13:15:07
  • Last modified 21.11.2024 07:54:50

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room

  • EPSS 4.5%
  • Published 15.03.2021 09:15:12
  • Last modified 21.11.2024 05:58:13

If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0

  • EPSS 51.7%
  • Published 30.09.2020 18:15:21
  • Last modified 21.11.2024 05:02:13

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

  • EPSS 0.18%
  • Published 28.02.2018 18:29:00
  • Last modified 21.11.2024 03:59:32

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

  • EPSS 6.15%
  • Published 12.10.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

  • EPSS 1.11%
  • Published 17.07.2017 13:18:30
  • Last modified 20.04.2025 01:37:25

Apache OpenMeetings 1.0.0 updates user password in insecure manner.