CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Apr 21, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the...Show more |
3Apache FasterxmlRedhat8Decision Manager GeodeJackson Databind+5 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+3 moreJun 17, 2026 Jan 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseKeycloak+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker...Show more |
2Redhat Smartbear3Jboss Fuse OpenshiftSwagger UiNov 21, 2024 Dec 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 swagger-ui has XSS in key names |
4Apache DebianFasterxml+1 more5Debian Linux Jackson Mapper AslJboss Enterprise Application Platform+2 moreJun 17, 2026 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. |
2Netapp Redhat7Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+4 moreJun 17, 2026 Oct 2, 2019 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. |
2Apache Redhat3Activemq Jboss A MqJboss FuseNov 21, 2024 Aug 1, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more |
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack. |
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the se...Show more |
2Hawt Redhat2Hawtio Jboss FuseNov 21, 2024 Jul 26, 2018 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseUndertow+1 moreNov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more |
2Hawt Redhat2Hawtio Jboss FuseMay 13, 2026 Dec 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. |
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated...Show more |
1Redhat 15Data Grid Jboss A MqJboss Bpm Suite+12 moreMay 13, 2026 Nov 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more |
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file. |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-...Show more |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to...Show more |
2Igniterealtime Redhat2Jboss Fuse Smack ApiMay 6, 2026 Oct 25, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi...Show more |