CVEs (243)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FasterxmlNetapp+2 more24Banking Platform ClusterwareCommunications Billing And Revenue Management+21 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readV...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jan 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to pat...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Wildfly Application ServerNov 21, 2024 Jan 24, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local file...Show more |
4Debian FasterxmlNetapp+1 more9Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 moreNov 21, 2024 Jan 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more |
1Redhat 2Enterprise Linux Jboss Enterprise Application PlatformNov 21, 2024 Jan 10, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an...Show more |
4Debian FasterxmlNetapp+1 more8Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+5 moreAug 27, 2025 Jan 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending malic...Show more |
1Redhat 6Hibernate Validator Jboss Enterprise Application PlatformSatellite+3 moreNov 21, 2024 Jan 10, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernat...Show more |
7Debian FujitsuNetapp+4 more45Adaptive Access Manager Application Testing SuiteClustered Data Ontap+42 moreMay 13, 2026 Nov 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use t...Show more |
1Redhat 15Data Grid Jboss A MqJboss Bpm Suite+12 moreMay 13, 2026 Nov 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more |
4Apache CanonicalDebian+1 more4Debian Linux Jboss Enterprise Application PlatformSolr+1 moreMay 13, 2026 Oct 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch,...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 21, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor...Show more |
6Apache CanonicalDebian+3 more58Active Iq Unified Manager Agile PlmCommunications Instant Messaging Server+55 moreApr 21, 2026 Oct 4, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Sep 19, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logg...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Sep 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact. |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Aug 22, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers. |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the...Show more |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that...Show more |
6Apache AppleDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 13, 2026 Jul 13, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Jun 8, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload. |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 May 19, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs d...Show more |