Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

446 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.0%—Redhat Jboss BPM SuiteRedhat Jboss DroolsRedhat Jboss Enterprise Brms Platform10/4/201417/6/2026
JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java code via a (1) MVFLEX Expression Language (MVEL) or (2) Drools expression.
ModificadaMedia (5.8)2.1%—Redhat Jboss Enterprise Application Platform3/4/201417/6/2026
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
ModificadaBaja (3.7)0.29%—Redhat Jboss Operations Network1/4/201416/6/2026
Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdirectories and files within the root directory, as demonstrated by obtaining JON credentials.
ModificadaBaja (3.5)0.81%—Redhat Jboss Operations Network1/4/201416/6/2026
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
ModificadaMedia (4.3)1.5%—Redhat Jboss WEB Framework KITRedhat Richfaces31/3/201417/6/2026
The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.
ModificadaBaja (1.9)0.35%—Redhat Jboss Enterprise Application Platform26/2/201417/6/2026
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
ModificadaMedia (4.3)1.0%—Redhat Jboss Enterprise Portal Platform26/2/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.8)1.1%—Redhat Jboss Enterprise Portal Platform26/2/201416/6/2026
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
ModificadaBaja (1.9)0.35%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server14/2/201417/6/2026
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.
ModificadaMedia (5.8)1.2%—Redhat Jboss Operations Network14/2/201416/6/2026
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
ModificadaMedia (5.8)1.1%—Redhat Jboss Operations Network14/2/201416/6/2026
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
ModificadaMedia (5.8)1.2%—Redhat Jboss Operations Network14/2/201416/6/2026
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
ModificadaMedia (5)2.2%—Redhat Jboss Communications PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise WEB Platform10/2/201416/6/2026
JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character"…
ModificadaBaja (2.1)0.35%—Redhat Jboss Enterprise Application Platform2/2/201416/6/2026
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
ModificadaMedia (5)1.4%—Redhat Jboss Seam 2 Framework23/1/201417/6/2026
The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.
ModificadaMedia (5)2.7%—Redhat Jboss Seam 2 Framework23/1/201417/6/2026
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via…
ModificadaAlta (7.5)7.2%—Apache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal Platform19/1/201416/6/2026
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186.…
ModificadaBaja (2.1)0.36%—Redhat Jboss Operations Network24/12/201316/6/2026
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.
ModificadaMedia (4.3)0.98%—Redhat Jboss Enterprise Portal Platform23/12/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.5)1.8%—Redhat Jboss Enterprise Application PlatformRedhat Enterprise Linux6/12/201316/6/2026
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging…
ModificadaAlta (7.5)13%💥 PoCRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise WEB ServerRedhat Openshift+128/10/201316/6/2026
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
ModificadaBaja (3.3)0.98%—Redhat Jboss Enterprise Portal Platform28/10/201316/6/2026
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
ModificadaBaja (3.7)0.34%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal Platform28/10/201316/6/2026
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications'…
ModificadaMedia (4.3)2.0%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform28/10/201316/6/2026
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a…
ModificadaBaja (3.2)0.30%—Redhat Jboss Operations Network24/10/201316/6/2026
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
Orbitaley — Vulnerabilidades