jboss kayıtları
jboss üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %14,3
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-255 Credentials Management Errors1
- CWE-20 Improper Input Validation1
- CWE-399 Resource Management Errors1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2007-1036Silahlaştırılmış | The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackjboss · jboss application server · CWE-264 | Yüksek7,5 | — | %82,3 | 21 Şub 2007 |
35İzleyin | CVE-2018-1041Kavram kanıtı | A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer.jboss · jboss-remoting · CWE-835 | Yüksek7,5 | — | %15,5 | 15 Şub 2018 |
35İzleyin | CVE-2003-0845Kavram kanıtı | Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, ajboss · jboss · CWE-89 | Yüksek7,5 | — | %15,4 | 17 Kas 2003 |
34İzleyin | CVE-2008-3273Silahlaştırılmış | JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtaijboss · enterprise application platform · CWE-264 | Orta5,0 | — | %47,1 | 10 Ağu 2008 |
34İzleyin | CVE-2006-5750İstismar yok | Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remjboss · jboss application server | Yüksek7,5 | — | %13,9 | 27 Kas 2006 |
31İzleyin | CVE-2007-6433İstismar yok | The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to injectjboss · seam · CWE-20 | Yüksek7,5 | — | %3,2 | 18 Ara 2007 |
31İzleyin | CVE-2016-2094İstismar yok | The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSLjboss · enterprise application platform · CWE-399 | Yüksek7,5 | — | %2,6 | 6 May 2016 |
30İzleyin | CVE-2005-2158İstismar yok | A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vuljboss · jbpm | Yüksek7,5 | — | %1,3 | 6 Tem 2005 |
30İzleyin | CVE-2007-1157İstismar yok | Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions asjboss · jboss · CWE-352 | Yüksek7,6 | — | %0,9 | 2 Mar 2007 |
24İzleyin | CVE-2007-1354İstismar yok | The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 usesjboss · jboss application server | Orta6,0 | — | %1,5 | 27 Tem 2007 |
23İzleyin | CVE-2005-2006Kavram kanıtı | JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot),jboss · jboss | Orta5,0 | — | %9,2 | 17 Haz 2005 |
21İzleyin | CVE-2005-4709İstismar yok | The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal andjboss · enterprise java beans | Orta5,0 | — | %2,2 | 31 Ara 2005 |
18İzleyin | CVE-2014-0170İstismar yok | Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary filesjboss · teiid | Orta4,3 | — | %2,0 | 30 Eyl 2014 |
17İzleyin | CVE-2012-3428İstismar yok | The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a securjboss · ironjacamar · CWE-255 | Orta4,3 | — | %1,4 | 20 Ara 2012 |
- CVE-2007-103655Planlayın
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attack
YüksekCVSS 7,5SilahlaştırılmışEPSS %82jboss · jboss application server21 Şub 2007
- CVE-2018-104135İzleyin
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer.
YüksekCVSS 7,5Kavram kanıtıEPSS %16jboss · jboss-remoting15 Şub 2018
- CVE-2003-084535İzleyin
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, a
YüksekCVSS 7,5Kavram kanıtıEPSS %15jboss · jboss17 Kas 2003
- CVE-2008-327334İzleyin
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtai
OrtaCVSS 5,0SilahlaştırılmışEPSS %47jboss · enterprise application platform10 Ağu 2008
- CVE-2006-575034İzleyin
Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows rem
YüksekCVSS 7,5İstismar yokEPSS %14jboss · jboss application server27 Kas 2006
- CVE-2007-643331İzleyin
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject
YüksekCVSS 7,5İstismar yokEPSS %3jboss · seam18 Ara 2007
- CVE-2016-209431İzleyin
The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL
YüksekCVSS 7,5İstismar yokEPSS %3jboss · enterprise application platform6 May 2016
- CVE-2005-215830İzleyin
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vul
YüksekCVSS 7,5İstismar yokEPSS %1jboss · jbpm6 Tem 2005
- CVE-2007-115730İzleyin
Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as
YüksekCVSS 7,6İstismar yokEPSS %1jboss · jboss2 Mar 2007
- CVE-2007-135424İzleyin
The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses
OrtaCVSS 6,0İstismar yokEPSS %1jboss · jboss application server27 Tem 2007
- CVE-2005-200623İzleyin
JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot),
OrtaCVSS 5,0Kavram kanıtıEPSS %9jboss · jboss17 Haz 2005
- CVE-2005-470921İzleyin
The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and
OrtaCVSS 5,0İstismar yokEPSS %2jboss · enterprise java beans31 Ara 2005
- CVE-2014-017018İzleyin
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files
OrtaCVSS 4,3İstismar yokEPSS %2jboss · teiid30 Eyl 2014
- CVE-2012-342817İzleyin
The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a secur
OrtaCVSS 4,3İstismar yokEPSS %1jboss · ironjacamar20 Ara 2012