CVEs (243)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote a...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which a...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Jul 22, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 moreMay 6, 2026 Jul 22, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not pro...Show more |
4Apache DebianOracle+1 more6Debian Linux Enterprise Manager Ops CenterHttp Server+3 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or ex...Show more |
3Apache DebianRedhat3Debian Linux Http ServerJboss Enterprise Application PlatformMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resourc...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss Web Framework KitMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute ar...Show more |
2Apache Redhat2Cxf Jboss Enterprise Application PlatformMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext,...Show more |
2Apache Redhat2Cxf Jboss Enterprise Application PlatformMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token. |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Apr 3, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.securi...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Feb 26, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files. |
1Redhat 2Jboss Enterprise Application Platform Jboss Wildfly Application ServerApr 29, 2026 Feb 14, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry...Show more |
1Redhat 4Jboss Communications Platform Jboss Enterprise Application PlatformJboss Enterprise Brms Platform+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Feb 2, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (...Show more |
2Apache Redhat3Jboss Enterprise Application Platform Jboss Enterprise Portal PlatformTomcatApr 29, 2026 Jan 19, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary...Show more |
1Redhat 2Enterprise Linux Jboss Enterprise Application PlatformApr 29, 2026 Dec 6, 2013 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, whi...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Portal PlatformApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 3.7 LOW· v2 Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loa...Show more |
1Redhat 2Jboss Community Application Server Jboss Enterprise Application PlatformApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allow...Show more |