CVEs (243)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Soa Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to...Show more |
1Redhat 5Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+2 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the...Show more |
1Redhat 2Jboss Enterprise Application Platform Mod ClusterApr 29, 2026 Oct 22, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote at...Show more |
1Redhat 2Jboss Community Application Server Jboss Enterprise Application PlatformApr 29, 2026 Aug 13, 2012 N/A· v4 N/A· v3 2.1 LOW· v2 twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Jan 27, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide...Show more |
3Kay Framework Project OpenidRedhat3Jboss Enterprise Application Platform Kay FrameworkOpenid4javaApr 29, 2026 Jan 27, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribut...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Soa PlatformJboss Enterprise Web Platform+1 moreApr 29, 2026 Jul 27, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Soa PlatformJboss Seam 2 FrameworkApr 29, 2026 Jul 27, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 a...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss RemotingApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of a...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss RemotingApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Soa PlatformApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of cla...Show more |
2Netapp Redhat4Jboss Enterprise Application Platform Oncommand BalanceOncommand Insight+1 moreApr 22, 2026 Aug 5, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Apr 28, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request t...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3....Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inje...Show more |