CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Infinispan Redhat3Data Grid InfinispanJboss Data GridJun 17, 2026 Dec 18, 2023 N/A· v4 2.7 LOW· v3 N/A· v2 A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text a...Show more |
2Infinispan Redhat3Data Grid InfinispanJboss Data GridJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and...Show more |
2Infinispan Redhat4Data Grid InfinispanJboss Data Grid+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of t...Show more |
2Infinispan Redhat4Data Grid InfinispanJboss Data Grid+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permiss...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
4Debian GnuRedhat+1 more4Debian Linux GzipJboss Data Grid+1 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arb...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
2Netapp Redhat10Active Iq Unified Manager FuseJboss Data Grid+7 moreJun 17, 2026 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain...Show more |
2Netapp Redhat10Data Grid Jboss Data GridJboss Enterprise Application Platform+7 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vuln...Show more |
1Redhat 4Jboss Data Grid Jboss Enterprise Application PlatformOpenshift Application Runtimes+1 moreJun 17, 2026 Sep 16, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400. |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Apr 21, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the...Show more |
3Apache FasterxmlRedhat8Decision Manager GeodeJackson Databind+5 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+3 moreJun 17, 2026 Jan 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridJun 17, 2026 Jan 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. |
3Infinispan NetappRedhat7Active Iq Unified Manager FuseInfinispan+4 moreJun 17, 2026 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The att...Show more |
3Netapp OracleRedhat188Access Manager Active Iq Unified ManagerAgile Engineering Data Management+185 moreJun 17, 2026 Nov 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can r...Show more |
2Netapp Redhat7Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+4 moreJun 17, 2026 Oct 2, 2019 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. |