Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
258 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.37% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform | 5/2/2013 | 16/6/2026 | The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file. | |
| Modificada | Media (4.9) | 2.2% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX… | |
| Modificada | Media (5.8) | 1.9% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to… | |
| Modificada | Media (4) | 2.7% | — | Redhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used. | |
| Modificada | Media (6.8) | 16% | 💥 Exploit | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote… | |
| Modificada | Baja (2.1) | 0.40% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.3) | 2.1% | — | Redhat Jboss Enterprise Application Platform | 5/1/2013 | 16/6/2026 | A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Jboss Enterprise Application Platform | 5/1/2013 | 16/6/2026 | A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass… | |
| Modificada | Media (4.6) | 1.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB Platform | 23/11/2012 | 16/6/2026 | The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the… | |
| Modificada | Alta (7.5) | 3.5% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+1 | 23/11/2012 | 16/6/2026 | The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write… | |
| Modificada | Media (6.8) | 2.9% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal Platform | 23/11/2012 | 16/6/2026 | The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request… | |
| Modificada | Media (4.3) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat MOD Cluster | 22/10/2012 | 16/6/2026 | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context… | |
| Modificada | Baja (2.1) | 0.39% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform | 13/8/2012 | 16/6/2026 | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | |
| Modificada | Alta (7.5) | 3.1% | — | Redhat Jboss Enterprise Application Platform | 27/1/2012 | 16/6/2026 | mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost… | |
| Modificada | Media (5.8) | 3.1% | — | KAY Framework Project KAY FrameworkOpenid4javaRedhat Jboss Enterprise Application Platform | 27/1/2012 | 16/6/2026 | message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially… | |
| Modificada | Media (6.8) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Seam 2 Framework | 27/7/2011 | 16/6/2026 | jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of… | |
| Modificada | Media (6.8) | 2.3% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Seam 2 Framework | 27/7/2011 | 16/6/2026 | jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages… | |
| Modificada | Baja (2.6) | 2.1% | — | Redhat Jboss RemotingRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform | 30/12/2010 | 16/6/2026 | The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of… | |
| Modificada | Media (4.3) | 0.87% | — | Redhat Jboss Enterprise Application Platform | 30/12/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests that deploy WAR files. | |
| Modificada | Baja (2.6) | 2.6% | — | Redhat Jboss RemotingRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform | 30/12/2010 | 16/6/2026 | The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka… | |
| Modificada | Alta (7.5) | 3.0% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA Platform | 30/12/2010 | 16/6/2026 | The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer. | |
| Analizada | Alta (8.8) | 83% | ⚠ Explotación activa💥 Exploit | Redhat Jboss Enterprise Application PlatformNetapp Oncommand BalanceNetapp Oncommand InsightNetapp Oncommand Unified Manager | 5/8/2010 | 16/6/2026 | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security… | |
| Modificada | Media (5) | 54% | 💥 Exploit | Redhat Jboss Enterprise Application Platform | 28/4/2010 | 16/6/2026 | Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because… | |
| Analizada | Alta (7.5) | 61% | ⚠ Explotación activa | Redhat Jboss Enterprise Application Platform | 28/4/2010 | 2/10/2026 | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that… |