← Back

Jboss Enterprise Application Platform

jboss_enterprise_application_platform

Vendor: Redhat • 243 CVEs

CVEs (243)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
4Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Soa Platform+1 more
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote at...Show more
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.Show less
2Jgroups
Redhat
2Jboss Enterprise Application Platform
Jgroup
Apr 29, 2026
Sep 28, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid crede...Show more
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.Show less
1Redhat
1Jboss Enterprise Application Platform
Apr 29, 2026
Sep 28, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
2Apache
Redhat
6Cxf
Jboss Enterprise Application PlatformJboss Enterprise Portal Platform+3 more
Apr 29, 2026
Aug 19, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting,...Show more
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."Show less
1Redhat
1Jboss Enterprise Application Platform
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
1Redhat
1Jboss Enterprise Application Platform
Apr 29, 2026
Aug 16, 2013
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
2Hp
Redhat
7Jboss Communications Platform
Jboss Enterprise Application PlatformJboss Enterprise Brms Platform+4 more
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP0...Show more
wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0; and JBoss Enterprise Web Platform 5.1.1 does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.Show less
1Redhat
8Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+5 more
Apr 29, 2026
Jul 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4....Show more
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations Network through 2.4.2 and 3.x through 3.1.2 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data.Show less
4Apache
CanonicalOpensuse+1 more
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which...Show more
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.Show less
5Apache
CanonicalOpensuse+2 more
10Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+7 more
Apr 29, 2026
Jun 10, 2013
N/A· v4
N/A· v3
5.1 MEDIUM· v2
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary command...Show more
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.Show less
1Redhat
2Jboss Enterprise Application Platform
Jboss Enterprise Web Platform
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote at...Show more
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.Show less
1Redhat
2Jboss Enterprise Application Platform
Jboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtai...Show more
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, whic...Show more
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials...Show more
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privil...Show more
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5...Show more
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an excep...Show more
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.Show less
1Redhat
3Jboss Enterprise Application Platform
Jboss Enterprise Brms PlatformJboss Enterprise Web Platform
Apr 29, 2026
Feb 5, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows r...Show more
Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Redhat
1Jboss Enterprise Application Platform
May 14, 2026
Jan 5, 2013
N/A· v4
5.3 MEDIUM· v3
6.4 MEDIUM· v2
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This preven...Show more
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.Show less
1Redhat
1Jboss Enterprise Application Platform
May 14, 2026
Jan 5, 2013
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are...Show more
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB methods, leading to unauthorized access to sensitive functionalities.Show less