Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.8% | — | Redhat Jboss Enterprise Application Platform | 10/9/2018 | 17/6/2026 | An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information. | |
| Modificada | Alta (7.5) | 6.6% | — | Dom4j Project Dom4jDebian LinuxOracle Flexcube Investor ServicingOracle Primavera P6 Enterprise Project Portfolio Management+10 | 20/8/2018 | 17/6/2026 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML… | |
| Modificada | Alta (7.5) | 20% | — | Apache TomcatRedhat Jboss Enterprise Application PlatformCanonical Ubuntu LinuxDebian Linux+4 | 2/8/2018 | 17/6/2026 | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86. | |
| Modificada | Alta (7.8) | 0.42% | — | Redhat Jboss Enterprise Application Platform | 31/7/2018 | 17/6/2026 | It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the… | |
| Modificada | Alta (7.5) | 3.6% | — | Redhat UndertowDebian LinuxRedhat Jboss Enterprise Application Platform | 27/7/2018 | 17/6/2026 | It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS. | |
| Modificada | Media (6.5) | 3.1% | — | Redhat Jboss Enterprise Application Platform | 27/7/2018 | 17/6/2026 | It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal. | |
| Modificada | Alta (7.5) | 1.9% | — | Redhat UndertowRedhat Jboss Enterprise Application Platform | 27/7/2018 | 17/6/2026 | It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling. | |
| Modificada | Media (5.5) | 1.3% | — | Redhat VirtualizationRedhat Jboss Enterprise Application PlatformRedhat Wildfly Core | 27/7/2018 | 17/6/2026 | WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability. | |
| Modificada | Media (6.5) | 3.1% | 💥 PoC | Redhat UndertowRedhat Jboss Enterprise Application PlatformDebian Linux | 27/7/2018 | 17/6/2026 | It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the… | |
| Modificada | Crítica (9.8) | 1.9% | — | Redhat Jboss Enterprise Application Platform | 27/7/2018 | 17/6/2026 | It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing. | |
| Modificada | Media (6.5) | 2.4% | — | Redhat KeycloakRedhat Jboss Enterprise Application Platform | 26/7/2018 | 17/6/2026 | It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be… | |
| Modificada | Media (5.5) | 0.38% | — | Redhat Jboss Enterprise Application Platform | 26/7/2018 | 17/6/2026 | It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system. | |
| Modificada | Alta (8.1) | 8.5% | 💥 PoC | Apache CXFRedhat Jboss Enterprise Application Platform | 2/7/2018 | 17/6/2026 | It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old… | |
| Modificada | Crítica (9.8) | 2.9% | — | Redhat Jboss Enterprise Application Platform | 27/6/2018 | 17/6/2026 | It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a… | |
| Modificada | Alta (7.5) | 3.6% | — | Bouncycastle Bc-javaBouncycastle Fips Java APIDebian LinuxOracle API Gateway+16 | 5/6/2018 | 17/6/2026 | Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA… | |
| Modificada | Alta (7.8) | 0.35% | — | Redhat Jboss Enterprise Application Platform | 22/5/2018 | 17/6/2026 | Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation. | |
| Modificada | Media (6.1) | 1.8% | — | Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Virtualization Host | 21/5/2018 | 17/6/2026 | In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an… | |
| Modificada | Media (6.5) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat Keycloak | 11/5/2018 | 17/6/2026 | admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal… | |
| Modificada | Media (5.9) | 5.1% | — | Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+13 | 26/4/2018 | 17/6/2026 | Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the… | |
| Modificada | Media (5.9) | 2.0% | — | Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Virtualization | 18/4/2018 | 17/6/2026 | undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the… | |
| Modificada | Crítica (9.8) | 15% | — | QOS Slf4jRedhat Jboss Enterprise Application PlatformRedhat VirtualizationRedhat Virtualization Host+9 | 20/3/2018 | 17/6/2026 | org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series. | |
| Modificada | Media (5.3) | 1.1% | — | Redhat Jboss Enterprise Application Platform | 9/3/2018 | 17/6/2026 | Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack. | |
| Modificada | Alta (7.5) | 6.0% | — | Apache ArtemisRedhat HornetqRedhat Jboss Enterprise Application Platform | 7/3/2018 | 17/6/2026 | It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError. | |
| Modificada | Media (5.9) | 17% | 💥 PoC | Apache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerDebian Linux+6 | 28/2/2018 | 17/6/2026 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore,… | |
| Modificada | Crítica (9.8) | 20% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Communications Instant Messaging Server+1 | 26/2/2018 | 17/6/2026 | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper,… |