İçeriğe atla
Noroxi

jboss kayıtları

jboss üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %14,3
Pre-auth RCE
4
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2007-1036
    55Planlayın

    The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attack

    YüksekCVSS 7,5SilahlaştırılmışEPSS %82

    jboss · jboss application server21 Şub 2007

  • CVE-2018-1041
    35İzleyin

    A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer.

    YüksekCVSS 7,5Kavram kanıtıEPSS %16

    jboss · jboss-remoting15 Şub 2018

  • CVE-2003-0845
    35İzleyin

    Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, a

    YüksekCVSS 7,5Kavram kanıtıEPSS %15

    jboss · jboss17 Kas 2003

  • CVE-2008-3273
    34İzleyin

    JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtai

    OrtaCVSS 5,0SilahlaştırılmışEPSS %47

    jboss · enterprise application platform10 Ağu 2008

  • CVE-2006-5750
    34İzleyin

    Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows rem

    YüksekCVSS 7,5İstismar yokEPSS %14

    jboss · jboss application server27 Kas 2006

  • CVE-2007-6433
    31İzleyin

    The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject

    YüksekCVSS 7,5İstismar yokEPSS %3

    jboss · seam18 Ara 2007

  • CVE-2016-2094
    31İzleyin

    The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL

    YüksekCVSS 7,5İstismar yokEPSS %3

    jboss · enterprise application platform6 May 2016

  • CVE-2005-2158
    30İzleyin

    A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vul

    YüksekCVSS 7,5İstismar yokEPSS %1

    jboss · jbpm6 Tem 2005

  • CVE-2007-1157
    30İzleyin

    Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as

    YüksekCVSS 7,6İstismar yokEPSS %1

    jboss · jboss2 Mar 2007

  • CVE-2007-1354
    24İzleyin

    The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses

    OrtaCVSS 6,0İstismar yokEPSS %1

    jboss · jboss application server27 Tem 2007

  • CVE-2005-2006
    23İzleyin

    JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot),

    OrtaCVSS 5,0Kavram kanıtıEPSS %9

    jboss · jboss17 Haz 2005

  • CVE-2005-4709
    21İzleyin

    The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and

    OrtaCVSS 5,0İstismar yokEPSS %2

    jboss · enterprise java beans31 Ara 2005

  • CVE-2014-0170
    18İzleyin

    Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files

    OrtaCVSS 4,3İstismar yokEPSS %2

    jboss · teiid30 Eyl 2014

  • CVE-2012-3428
    17İzleyin

    The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a secur

    OrtaCVSS 4,3İstismar yokEPSS %1

    jboss · ironjacamar20 Ara 2012