CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 10Build Of Keycloak Jboss Middleware Text Only AdvisoriesKeycloak+7 moreJun 17, 2026 Apr 17, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive...Show more |
2Quarkus Redhat12Build Of Optaplanner Build Of QuarkusDecision Manager+9 moreJun 17, 2026 Sep 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an at...Show more |
1Redhat 4Decision Manager DroolsJboss Middleware Text Only Advisories+1 moreJun 17, 2026 Sep 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadge...Show more |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
2Apache Redhat10Cxf Jboss Business Rules Management SystemJboss Enterprise Application Platform+7 moreNov 21, 2024 Mar 11, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. |
6Apache DebianFasterxml+3 more18Banking Platform Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more |
3Apache OracleRedhat5Database Jboss Middleware Text Only AdvisoriesKafka+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data r...Show more |
3Apache NettyRedhat4Cassandra Jboss Data GridJboss Middleware Text Only Advisories+1 moreMay 13, 2026 Apr 13, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). |
2Apache Redhat4Aurora FuseJboss Middleware Text Only Advisories+1 moreApr 22, 2026 Jun 7, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para...Show more |