Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)4.0%—Redhat Jboss BrmsRedhat Jboss Drools10/9/201817/6/2026
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.
ModificadaAlta (7.5)6.6%—Dom4j Project Dom4jDebian LinuxOracle Flexcube Investor ServicingOracle Primavera P6 Enterprise Project Portfolio Management+1020/8/201817/6/2026
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML…
ModificadaMedia (6.5)1.2%—Redhat Jboss Core ServicesXmlsoft Libxml216/8/201817/6/2026
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML document. NOTE: this vulnerability exists because of a missing fix for CVE-2016-4483.
ModificadaMedia (6.5)1.1%—Redhat Jboss Core ServicesXmlsoft Libxml216/8/201817/6/2026
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-3627.
ModificadaAlta (7.5)20%—Apache TomcatRedhat Jboss Enterprise Application PlatformCanonical Ubuntu LinuxDebian Linux+42/8/201817/6/2026
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
ModificadaMedia (5.3)1.9%—Redhat Jboss A-mqRedhat Jboss Fuse1/8/201817/6/2026
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
ModificadaAlta (7.2)2.0%—Redhat Jboss A-mqRedhat Jboss Fuse1/8/201817/6/2026
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization…
ModificadaMedia (5.4)1.3%—Redhat Jboss BPM SuiteRedhat Jboss Business Rules Management System1/8/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users,…
ModificadaAlta (7.8)0.42%—Redhat Jboss Enterprise Application Platform31/7/201817/6/2026
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the…
ModificadaMedia (6.1)1.8%—Redhat Jboss BPM Suite27/7/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the…
ModificadaMedia (5.4)1.3%—Redhat Jboss BPM Suite27/7/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized…
ModificadaMedia (6.5)1.5%—Redhat Jboss BPM SuiteRedhat Jboss Data Virtualization & Services27/7/201817/6/2026
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing…
ModificadaAlta (7.5)3.6%—Redhat UndertowDebian LinuxRedhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
ModificadaMedia (6.5)3.1%—Redhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
ModificadaAlta (7.5)1.9%—Redhat UndertowRedhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
ModificadaMedia (5.5)1.3%—Redhat VirtualizationRedhat Jboss Enterprise Application PlatformRedhat Wildfly Core27/7/201817/6/2026
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
ModificadaMedia (6.5)3.1%💥 PoCRedhat UndertowRedhat Jboss Enterprise Application PlatformDebian Linux27/7/201817/6/2026
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the…
ModificadaCrítica (9.8)1.9%—Redhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
ModificadaMedia (6.5)2.4%—Redhat KeycloakRedhat Jboss Enterprise Application Platform26/7/201817/6/2026
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be…
ModificadaMedia (5.5)0.38%—Redhat Jboss Enterprise Application Platform26/7/201817/6/2026
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
ModificadaMedia (6.5)2.7%—Redhat Decision ManagerRedhat Jboss BPM SuiteRedhat Jbpm26/7/201817/6/2026
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE)…
ModificadaCrítica (9)0.93%—HawtioRedhat Jboss Fuse26/7/201817/6/2026
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
ModificadaMedia (5.4)4.8%—Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+126/7/201817/6/2026
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
ModificadaMedia (6.5)1.6%—InfinispanRedhat Jboss Data Grid16/7/201817/6/2026
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
ModificadaAlta (8.1)8.5%💥 PoCApache CXFRedhat Jboss Enterprise Application Platform2/7/201817/6/2026
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old…
Orbitaley — Vulnerabilidades