Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.53% | — | Redhat Build OF QuarkusRedhat Data GridRedhat Descision ManagerRedhat Integration Camel K+5 | 20/5/2021 | 17/6/2026 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity. | |
| Modificada | Media (5.9) | 1.1% | — | Redhat Wildfly | 8/12/2020 | 17/6/2026 | A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw allows an attacker to impact the availability of the server. The highest threat… | |
| Modificada | Media (5.3) | 1.3% | — | Redhat Wildfly | 24/11/2020 | 17/6/2026 | A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat WildflyRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 2/11/2020 | 17/6/2026 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a… | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat Wildfly OpensslRedhat Data GridRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 6/10/2020 | 17/6/2026 | A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Wildfly ElytronRedhat Codeready StudioRedhat Descision ManagerRedhat Jboss Fuse+2 | 23/9/2020 | 17/6/2026 | A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (7.5) | 1.4% | — | Redhat Jboss FuseRedhat Wildfly | 16/9/2020 | 17/6/2026 | A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (7.5) | 1.4% | — | Redhat Wildfly ElytronRedhat Decision ManagerRedhat Process Automation | 16/9/2020 | 17/6/2026 | A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources. | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat Wildfly | 22/6/2020 | 17/6/2026 | A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly. | |
| Modificada | Crítica (9.1) | 1.1% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+2 | 16/3/2020 | 17/6/2026 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a… | |
| Modificada | Media (4.9) | 1.1% | — | Redhat Wildfly CoreRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Data Grid | 14/10/2019 | 17/6/2026 | A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server | |
| Modificada | Alta (8.8) | 1.5% | — | Redhat WildflyRedhat Jboss Enterprise Application Platform | 3/5/2019 | 17/6/2026 | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing. | |
| Modificada | Media (4.7) | 0.19% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 3/5/2019 | 17/6/2026 | A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Wildfly Deployer | 4/4/2019 | 17/6/2026 | Jenkins WildFly Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (5.9) | 1.1% | — | Redhat Wildfly | 4/9/2018 | 17/6/2026 | The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/> | |
| Modificada | Media (5.5) | 1.3% | — | Redhat VirtualizationRedhat Jboss Enterprise Application PlatformRedhat Wildfly Core | 27/7/2018 | 17/6/2026 | WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Redhat Wildfly | 9/5/2018 | 17/6/2026 | An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference"… | |
| Modificada | Crítica (9.8) | 8.3% | — | Wildfly | 9/5/2018 | 17/6/2026 | An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to… | |
| Modificada | Alta (7.5) | 3.0% | — | Redhat Jboss Wildfly Application Server | 12/3/2018 | 17/6/2026 | Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) *… | |
| Modificada | Media (5.5) | 0.51% | 💥 PoC | Redhat Jboss Wildfly Application ServerRedhat Jboss Enterprise Application Platform | 24/1/2018 | 17/6/2026 | A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files. | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Jboss Wildfly Application Server | 21/7/2017 | 17/6/2026 | The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL. | |
| Modificada | Media (6.1) | 2.5% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 26/9/2016 | 17/6/2026 | CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Redhat Jboss Wildfly Application Server | 1/4/2016 | 17/6/2026 | Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless"… | |
| Modificada | Media (5) | 3.0% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 27/10/2015 | 17/6/2026 | The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header. | |
| Modificada | Media (6.8) | 1.1% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server | 27/10/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an… |