CVEs (243)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreMay 28, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
2Postgresql Redhat2Jboss Enterprise Application Platform PostgresqlNov 21, 2024 Oct 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is...Show more |
2Quarkus Redhat13Build Of Quarkus Codeready StudioData Grid+10 moreNov 21, 2024 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnera...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreNov 21, 2024 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
1Redhat 2Jboss Enterprise Application Platform WildflyNov 21, 2024 Jun 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit th...Show more |
2Postgresql Redhat4Enterprise Linux Jboss Enterprise Application PlatformPostgresql+1 moreNov 21, 2024 Jun 1, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write ar...Show more |
4Debian FedoraprojectOpenldap+1 more7Debian Linux Enterprise LinuxFedora+4 moreNov 21, 2024 May 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulner...Show more |
1Redhat 4Fuse Jboss Enterprise Application PlatformOpenshift Application Runtimes+1 moreNov 21, 2024 May 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could us...Show more |
1Redhat 9Build Of Quarkus Data GridDescision Manager+6 moreNov 21, 2024 May 20, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality...Show more |
2Netapp Redhat4Active Iq Unified Manager Jboss Enterprise Application PlatformJboss Remoting+1 moreNov 21, 2024 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versi...Show more |
2Netapp Redhat10Active Iq Unified Manager FuseJboss Data Grid+7 moreNov 21, 2024 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain...Show more |
1Redhat 3Jboss Enterprise Application Platform Openshift Application RuntimesSingle Sign OnNov 21, 2024 Oct 16, 2020 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an at...Show more |
2Netapp Redhat10Data Grid Jboss Data GridJboss Enterprise Application Platform+7 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vuln...Show more |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnUndertowNov 21, 2024 Sep 23, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP...Show more |
1Redhat 4Jboss Data Grid Jboss Enterprise Application PlatformOpenshift Application Runtimes+1 moreNov 21, 2024 Sep 16, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400. |
1Redhat 2Jboss Enterprise Application Platform JbosswebNov 21, 2024 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invali...Show more |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreNov 21, 2024 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
2Netapp Redhat4Jboss Enterprise Application Platform Oncommand InsightOpenshift Application Runtimes+1 moreNov 21, 2024 Jun 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of servic...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreNov 21, 2024 May 26, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. |
4Ibm OracleQuarkus+1 more7Hibernate Validator Jboss Enterprise Application PlatformQuarkus+4 moreNov 21, 2024 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input s...Show more |