Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.97%—Redhat Jboss Enterprise Portal Platform18/1/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.3)2.1%—Redhat Jboss Enterprise Application Platform5/1/201316/6/2026
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing…
ModificadaMedia (6.5)1.3%—Redhat Jboss Enterprise Application Platform5/1/201316/6/2026
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass…
ModificadaMedia (4.3)1.4%—Jboss Ironjacamar20/12/201216/6/2026
The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in…
ModificadaMedia (4.3)1.8%—Redhat Jboss Enterprise Data Services Platform23/11/201216/6/2026
The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack.
ModificadaBaja (3.3)1.4%—Redhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise Brms Platform23/11/201216/6/2026
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
ModificadaMedia (4.6)1.6%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB Platform23/11/201216/6/2026
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the…
ModificadaAlta (7.5)3.5%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+123/11/201216/6/2026
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write…
ModificadaMedia (6.8)2.9%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal Platform23/11/201216/6/2026
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request…
ModificadaMedia (6)1.6%—Redhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform23/11/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on…
ModificadaMedia (5)2.6%—Redhat Jboss Enterprise Portal Platform23/11/201216/6/2026
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses,…
ModificadaMedia (4.3)2.6%—Redhat Jboss Enterprise Application PlatformRedhat MOD Cluster22/10/201216/6/2026
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context…
ModificadaBaja (2.1)0.39%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform13/8/201216/6/2026
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
ModificadaMedia (4.3)82%💥 ExploitApache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+728/1/201216/6/2026
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with…
ModificadaAlta (7.5)3.1%—Redhat Jboss Enterprise Application Platform27/1/201216/6/2026
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost…
ModificadaMedia (5.8)3.1%—KAY Framework Project KAY FrameworkOpenid4javaRedhat Jboss Enterprise Application Platform27/1/201216/6/2026
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially…
ModificadaMedia (4.6)2.8%💥 ExploitApache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+818/1/201216/6/2026
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
ModificadaMedia (4.3)1.1%—Redhat Jboss Operations NetworkRhq-project RHQ8/1/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)22%—Apache Http ServerRedhat Jboss Enterprise WEB Server20/9/201116/6/2026
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
ModificadaMedia (6.8)2.6%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Seam 2 Framework27/7/201116/6/2026
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of…
ModificadaMedia (6.8)2.3%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Seam 2 Framework27/7/201116/6/2026
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages…
ModificadaBaja (2.6)2.1%—Redhat Jboss RemotingRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform30/12/201016/6/2026
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of…
ModificadaMedia (4.3)0.87%—Redhat Jboss Enterprise Application Platform30/12/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests that deploy WAR files.
ModificadaBaja (2.6)2.6%—Redhat Jboss RemotingRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform30/12/201016/6/2026
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka…
ModificadaAlta (7.5)3.0%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise SOA Platform30/12/201016/6/2026
The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.
Orbitaley — Vulnerabilidades