Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
258 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+2 | 16/3/2020 | 17/6/2026 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a… | |
| Modificada | Media (5.9) | 1.8% | — | Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+6 | 11/3/2020 | 16/6/2026 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | |
| Modificada | Crítica (9.8) | 5.6% | — | Fasterxml Jackson-databindRedhat Decision ManagerRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+4 | 2/3/2020 | 17/6/2026 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code. | |
| Modificada | Crítica (9.1) | 13% | — | NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+3 | 29/1/2020 | 17/6/2026 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. | |
| Modificada | Crítica (9.1) | 8.9% | — | NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 29/1/2020 | 17/6/2026 | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold." | |
| Modificada | Alta (7.5) | 3.6% | — | NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+2 | 27/1/2020 | 17/6/2026 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869. | |
| Modificada | Media (4.3) | 0.74% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 23/1/2020 | 17/6/2026 | A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information. | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+2 | 23/1/2020 | 16/6/2026 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+2 | 23/1/2020 | 17/6/2026 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL. | |
| Modificada | Media (4.3) | 0.72% | — | Redhat KeycloakRedhat Single Sign-onRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse | 8/1/2020 | 17/6/2026 | It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information. | |
| Modificada | Alta (8.8) | 1.2% | — | Redhat Single Sign-onRedhat Jboss Enterprise Application Platform | 7/1/2020 | 17/6/2026 | A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7… | |
| Modificada | Media (6.5) | 0.78% | — | Redhat Jboss Enterprise Application Platform | 2/1/2020 | 17/6/2026 | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality,… | |
| Modificada | Alta (7.8) | 0.29% | — | Redhat Jboss Application ServerRedhat Jboss Enterprise Application Platform | 18/12/2019 | 16/6/2026 | An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges. | |
| Modificada | Media (6.1) | 0.65% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Portal | 11/12/2019 | 17/6/2026 | JBossWeb Bayeux has reflected XSS | |
| Modificada | Alta (8.8) | 3.1% | — | InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+3 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | |
| Modificada | Alta (7.5) | 17% | 💥 PoC | Fasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+1 | 18/11/2019 | 17/6/2026 | A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.5) | 6.4% | — | Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function | 29/10/2019 | 17/6/2026 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. | |
| Modificada | Alta (7.5) | 9.2% | — | Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function | 29/10/2019 | 17/6/2026 | In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. | |
| Modificada | Media (4.9) | 1.1% | — | Redhat Wildfly CoreRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Data Grid | 14/10/2019 | 17/6/2026 | A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server | |
| Modificada | Crítica (9.8) | 5.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+18 | 12/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide… | |
| Modificada | Crítica (9.8) | 4.6% | — | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+8 | 7/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. | |
| Modificada | Crítica (9.8) | 1.9% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+3 | 2/10/2019 | 17/6/2026 | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. | |
| Modificada | Crítica (9.8) | 4.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+22 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint… | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+24 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service… |