← Back

Jboss Fuse

jboss_fuse

Vendor: Redhat • 42 CVEs

CVEs (42)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
6Jboss Data Grid
Jboss Enterprise Application PlatformJboss Fuse+3 more
Jun 17, 2026
Apr 21, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize...Show more
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.Show less
1Redhat
6Jboss Data Grid
Jboss Enterprise Application PlatformJboss Fuse+3 more
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the...Show more
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed over the network. Wildfly version 7.2.0.GA, 7.2.3.GA and 7.2.5.CR2 are believed to be vulnerable.Show less
3Apache
FasterxmlRedhat
8Decision Manager
GeodeJackson Databind+5 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.Show less
2Netapp
Redhat
6Active Iq Unified Manager
Jboss Data GridJboss Enterprise Application Platform+3 more
Jun 17, 2026
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on...Show more
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.Show less
1Redhat
4Jboss Enterprise Application Platform
Jboss FuseKeycloak+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker...Show more
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.Show less
2Redhat
Smartbear
3Jboss Fuse
OpenshiftSwagger Ui
Nov 21, 2024
Dec 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
swagger-ui has XSS in key names
4Apache
DebianFasterxml+1 more
5Debian Linux
Jackson Mapper AslJboss Enterprise Application Platform+2 more
Jun 17, 2026
Nov 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
2Netapp
Redhat
7Active Iq Unified Manager
Jboss Data GridJboss Enterprise Application Platform+4 more
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
2Apache
Redhat
3Activemq
Jboss A MqJboss Fuse
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.Show less
1Redhat
2Jboss A Mq
Jboss Fuse
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
1Redhat
2Jboss A Mq
Jboss Fuse
Nov 21, 2024
Aug 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the se...Show more
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.Show less
2Hawt
Redhat
2Hawtio
Jboss Fuse
Nov 21, 2024
Jul 26, 2018
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.Show less
1Redhat
4Jboss Enterprise Application Platform
Jboss FuseUndertow+1 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.Show less
2Hawt
Redhat
2Hawtio
Jboss Fuse
May 13, 2026
Dec 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
2Hawt
Redhat
2Hawtio
Jboss Fuse
May 13, 2026
Dec 29, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated...Show more
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."Show less
1Redhat
15Data Grid
Jboss A MqJboss Bpm Suite+12 more
May 13, 2026
Nov 9, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.Show less
1Redhat
1Jboss Fuse
May 6, 2026
Jul 8, 2015
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
2Async Http Client Project
Redhat
2Async Http Client
Jboss Fuse
May 6, 2026
Jun 24, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-...Show more
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.Show less
2Async Http Client Project
Redhat
2Async Http Client
Jboss Fuse
May 6, 2026
Jun 24, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to...Show more
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.Show less
2Igniterealtime
Redhat
2Jboss Fuse
Smack Api
May 6, 2026
Oct 25, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi...Show more
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less