CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreMar 31, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, whic...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreMar 31, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in he...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+6 moreApr 10, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions o...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreApr 8, 2026 Mar 24, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods lik...Show more |
1Redhat 8Build Of Apache Camel Data GridFuse+5 moreMar 18, 2026 Jan 7, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,...Show more |
1Redhat 8Build Of Apache Camel For Spring Boot Enterprise LinuxFuse+5 moreMar 18, 2026 Sep 2, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to indu...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootBuild Of Keycloak+6 moreJan 19, 2026 Aug 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple request...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreMay 12, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreNov 21, 2024 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
1Redhat 4Decision Manager DroolsJboss Middleware Text Only Advisories+1 moreNov 21, 2024 Sep 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadge...Show more |
1Redhat 2Decision Manager Process AutomationMay 13, 2025 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console. |
1Redhat 9A Mq Streams Build Of QuarkusDescision Manager+6 moreNov 21, 2024 Aug 24, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supp...Show more |
1Redhat 3Business Central Descision ManagerProcess AutomationNov 21, 2024 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. |
1Redhat 5Descision Manager Jboss Enterprise Application PlatformJboss Enterprise Application Platform Expansion Pack+2 moreNov 21, 2024 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreMay 28, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
2Quarkus Redhat13Build Of Quarkus Codeready StudioData Grid+10 moreNov 21, 2024 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnera...Show more |
1Redhat 3Descision Manager JbpmProcess AutomationNov 21, 2024 Jun 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The...Show more |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreNov 21, 2024 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |
2Netapp Redhat6Codeready Studio Descision ManagerJboss Fuse+3 moreNov 21, 2024 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat fr...Show more |
1Redhat 3Decision Manager Process AutomationWildfly ElytronNov 21, 2024 Sep 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorizatio...Show more |