Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
446 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.1% | — | Redhat Jboss Weld | 13/2/2015 | 17/6/2026 | Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state. | |
| Modificada | Media (4) | 1.2% | — | Redhat Jboss Operations NetworkRedhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging… | |
| Modificada | Media (4) | 1.3% | — | Redhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role. | |
| Modificada | Baja (3.5) | 1.7% | — | Redhat Jboss Enterprise Application Platform | 13/2/2015 | 17/6/2026 | The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by… | |
| Modificada | Media (5) | 2.1% | — | Redhat Jboss Data VirtualizationOdata4j Project Odata4j | 15/1/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint. | |
| Modificada | Media (4.3) | 0.97% | — | Redhat Jboss Enterprise Portal Platform | 11/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file. | |
| Modificada | Baja (2.1) | 0.35% | — | Redhat Jboss Enterprise Application Platform | 17/11/2014 | 17/6/2026 | JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Media (6.8) | 0.92% | — | Redhat Jboss FuseIgniterealtime Smack API | 25/10/2014 | 17/6/2026 | The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an… | |
| Modificada | Media (4.3) | 2.0% | — | Redhat Jboss Data VirtualizationJboss Teiid | 30/9/2014 | 17/6/2026 | Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (7.5) | 4.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Resteasy | 19/8/2014 | 17/6/2026 | RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified… | |
| Modificada | Media (4.9) | 1.7% | — | Redhat Jboss Enterprise Application Platform | 19/8/2014 | 17/6/2026 | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors. | |
| Modificada | Media (5.5) | 1.1% | — | Redhat Jboss Enterprise Application Platform | 19/8/2014 | 17/6/2026 | The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging… | |
| Modificada | Alta (7.5) | 3.9% | — | Redhat Jboss Enterprise Application Platform | 22/7/2014 | 17/6/2026 | The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified… | |
| Modificada | Media (6.8) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform | 22/7/2014 | 17/6/2026 | jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to execute arbitrary code… | |
| Modificada | Media (6.8) | 86% | 💥 Exploit | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Enterprise Manager OPS Center+2 | 20/7/2014 | 17/6/2026 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the… | |
| Modificada | Media (4.3) | 37% | — | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application Platform | 20/7/2014 | 17/6/2026 | The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size. | |
| Modificada | Media (5) | 3.0% | — | Redhat Jboss Enterprise Application Platform | 7/7/2014 | 17/6/2026 | org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (6.8) | 3.5% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss WEB Framework KIT | 7/7/2014 | 17/6/2026 | org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging. | |
| Modificada | Media (4.3) | 7.1% | — | Apache CXFRedhat Jboss Enterprise Application Platform | 7/7/2014 | 17/6/2026 | The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (4.3) | 7.4% | — | Apache CXFRedhat Jboss Enterprise Application Platform | 7/7/2014 | 17/6/2026 | The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token. | |
| Modificada | Alta (7.4) | 95% | 💥 PoC | OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+12 | 5/6/2014 | 17/6/2026 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive… | |
| Modificada | Media (4.3) | 0.99% | — | Redhat Jboss WEB Framework KIT | 5/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name. | |
| Modificada | Media (6.5) | 1.7% | — | Redhat Jboss Fuse Service WorksRedhat Jboss Overlord RUN Time Governance | 22/4/2014 | 17/6/2026 | JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Jboss A-mqRedhat Jboss Fuse | 17/4/2014 | 17/6/2026 | JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs… | |
| Modificada | Media (5) | 53% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+11 | 15/4/2014 | 16/6/2026 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." |