Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Redhat Single Sign-on | 26/5/2021 | 17/6/2026 | An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges. | |
| Modificada | Media (6.8) | 0.33% | — | Redhat KeycloakRedhat Single Sign-on | 9/3/2021 | 17/6/2026 | A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system… | |
| Modificada | Media (6.5) | 18% | 💥 Exploit | Redhat KeycloakRedhat Single Sign-on | 8/3/2021 | 17/6/2026 | A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data… | |
| Modificada | Baja (2.7) | 0.77% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. | |
| Modificada | Baja (3.3) | 0.21% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable. | |
| Modificada | Baja (2.7) | 0.96% | — | Redhat Single Sign-on | 12/1/2021 | 17/6/2026 | The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an… | |
| Modificada | Media (6.5) | 1.5% | — | Redhat WildflyRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 2/11/2020 | 17/6/2026 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a… | |
| Modificada | Alta (7.9) | 0.73% | — | Vmware Single Sign-on FOR Tanzu | 31/10/2020 | 17/6/2026 | Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two different identity providers, one can acquire… | |
| Modificada | Media (6.5) | 1.4% | — | Redhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on | 16/10/2020 | 17/6/2026 | A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The… | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat Wildfly OpensslRedhat Data GridRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 6/10/2020 | 17/6/2026 | A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (4.8) | 1.2% | — | Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 23/9/2020 | 17/6/2026 | A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain… | |
| Modificada | Media (6.1) | 0.93% | — | Redhat KeycloakRedhat Single Sign-on | 16/9/2020 | 17/6/2026 | A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks. | |
| Modificada | Alta (7.5) | 1.9% | — | Redhat KeycloakRedhat Openshift Application RuntimesRedhat Single Sign-on | 16/9/2020 | 17/6/2026 | A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body. | |
| Modificada | Media (5.3) | 1.2% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on | 16/9/2020 | 17/6/2026 | The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400. | |
| Modificada | Media (6.5) | 1.2% | — | Redhat AMQRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss FuseRedhat Openshift Application Runtimes+1 | 24/7/2020 | 17/6/2026 | A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat AMQRedhat Jboss-ejb-clientRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss Fuse+2 | 24/7/2020 | 17/6/2026 | A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services… | |
| Modificada | Media (6.5) | 2.1% | 💥 PoC | Hibernate ORMRedhat Build OF QuarkusRedhat Decision ManagerRedhat Fuse+6 | 6/7/2020 | 17/6/2026 | A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or… | |
| Modificada | Media (6.5) | 0.98% | — | Redhat UndertowNetapp Oncommand InsightRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 26/5/2020 | 17/6/2026 | A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. | |
| Modificada | Alta (8.8) | 2.6% | — | Redhat KeycloakRedhat Decision ManagerRedhat Jboss FuseRedhat Openshift Application Runtimes+3 | 13/5/2020 | 17/6/2026 | A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution. | |
| Modificada | Media (4.3) | 0.82% | — | Redhat KeycloakRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/5/2020 | 17/6/2026 | A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section. | |
| Modificada | Alta (8.1) | 1.6% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+2 | 21/4/2020 | 17/6/2026 | A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping… | |
| Modificada | Crítica (9.1) | 1.1% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+2 | 16/3/2020 | 17/6/2026 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a… | |
| Modificada | Media (5.4) | 0.76% | — | Redhat KeycloakRedhat Single Sign-on | 10/2/2020 | 17/6/2026 | It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks. | |
| Modificada | Media (4.3) | 0.74% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 23/1/2020 | 17/6/2026 | A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information. | |
| Modificada | Alta (7.5) | 2.1% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+2 | 23/1/2020 | 17/6/2026 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL. |