Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.2) | 0.30% | — | Redhat Jboss Operations Network | 24/10/2013 | 16/6/2026 | The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files. | |
| Modificada | Baja (2.1) | 0.34% | — | Redhat Jboss Operations Network | 24/10/2013 | 16/6/2026 | The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files. | |
| Modificada | Media (5) | 2.7% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB Platform | 1/10/2013 | 16/6/2026 | The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | Redhat Jboss A-mqRedhat Jboss Fuse | 30/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page. | |
| Modificada | Media (5.4) | 1.6% | — | Jgroups JgroupRedhat Jboss Enterprise Application Platform | 28/9/2013 | 16/6/2026 | The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials. | |
| Modificada | Baja (1.9) | 0.24% | — | Redhat Jboss Enterprise Application Platform | 28/9/2013 | 16/6/2026 | PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file. | |
| Modificada | Media (6.4) | 6.3% | 💥 PoC | Apache CXFRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+2 | 19/8/2013 | 16/6/2026 | Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended… | |
| Modificada | Media (6.4) | 2.5% | — | Redhat Jboss Enterprise Application Platform | 16/8/2013 | 16/6/2026 | Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client. | |
| Modificada | Media (6.4) | 2.5% | — | Redhat Jboss Enterprise Application Platform | 16/8/2013 | 16/6/2026 | Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client. | |
| Modificada | Media (5) | 2.7% | — | Redhat Jboss Communications PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal Platform+3 | 29/7/2013 | 16/6/2026 | wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0;… | |
| Modificada | Alta (7.5) | 13% | 💥 PoC | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+4 | 23/7/2013 | 16/6/2026 | ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform… | |
| Modificada | Media (4.3) | 29% | — | Apache Http ServerRedhat Jboss Enterprise Application PlatformRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 10/7/2013 | 16/6/2026 | mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML… | |
| Modificada | Media (6.9) | 0.37% | — | Redhat Jboss Enterprise WEB ServerRedhat Enterprise Linux | 9/7/2013 | 16/6/2026 | The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log,… | |
| Modificada | Media (5.1) | 25% | — | Apache Http ServerRedhat Jboss Enterprise Application PlatformOracle Http ServerRedhat Enterprise Linux Desktop+6 | 10/6/2013 | 16/6/2026 | mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 1.4% | — | Redhat Jboss Enterprise Portal Platform | 12/4/2013 | 16/6/2026 | The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Jboss Enterprise Portal Platform | 12/4/2013 | 16/6/2026 | The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets. | |
| Modificada | Media (6.8) | 0.66% | — | Redhat Jboss Enterprise Portal Platform | 12/4/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform | 12/3/2013 | 16/6/2026 | The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform | 5/2/2013 | 16/6/2026 | The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file. | |
| Modificada | Media (4.9) | 2.2% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX… | |
| Modificada | Media (5.8) | 1.9% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to… | |
| Modificada | Media (4) | 2.7% | — | Redhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used. | |
| Modificada | Media (6.8) | 16% | 💥 Exploit | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote… | |
| Modificada | Baja (2.1) | 0.40% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms Platform | 5/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |