CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Redhat10Cxf Jboss Business Rules Management SystemJboss Enterprise Application Platform+7 moreNov 21, 2024 Mar 11, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss Web Framework KitMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute ar...Show more |
9Fedoraproject Filezilla ProjectMariadb+6 more16Application Processing Engine Firmware Cp1543 1 FirmwareEnterprise Linux+13 moreMay 6, 2026 Jun 5, 2014 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more |
1Redhat 4Jboss Communications Platform Jboss Enterprise Application PlatformJboss Enterprise Brms Platform+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Soa Platform+1 moreApr 29, 2026 Oct 1, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote at...Show more |
2Apache Redhat6Cxf Jboss Enterprise Application PlatformJboss Enterprise Portal Platform+3 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting,...Show more |
2Hp Redhat7Jboss Communications Platform Jboss Enterprise Application PlatformJboss Enterprise Brms Platform+4 moreApr 29, 2026 Jul 29, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP0...Show more |
1Redhat 8Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+5 moreApr 29, 2026 Jul 23, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4....Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Web PlatformApr 29, 2026 Mar 12, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote at...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtai...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, whic...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privil...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an excep...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Web PlatformApr 29, 2026 Feb 5, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows r...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Soa Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to...Show more |
1Redhat 5Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+2 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Soa PlatformJboss Enterprise Web Platform+1 moreApr 29, 2026 Jul 27, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss RemotingApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform...Show more |