Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 87% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+18 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a… | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Crítica (9.8) | 8.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+20 | 29/7/2019 | 17/6/2026 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. | |
| Modificada | Alta (7.5) | 3.5% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+2 | 25/7/2019 | 17/6/2026 | undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. | |
| Modificada | Media (6.1) | 1.1% | — | Miniorange Saml SP Single Sign ON | 24/6/2019 | 17/6/2026 | In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post. | |
| Modificada | Media (4.8) | 0.29% | — | Redhat KeycloakRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network… | |
| Modificada | Crítica (9) | 0.91% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks. | |
| Modificada | Media (5.4) | 0.69% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks. | |
| Modificada | Media (5.5) | 0.21% | — | Redhat KeycloakRedhat Single Sign-on | 12/6/2019 | 17/6/2026 | It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely. | |
| Modificada | Media (5.4) | 0.95% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on | 27/3/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users. | |
| Modificada | Alta (7.5) | 8.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service… | |
| Modificada | Alta (7.5) | 7.2% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraOracle JD Edwards Enterpriseone Tools+7 | 21/3/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access,… | |
| Modificada | Alta (8.1) | 1.2% | — | Redhat KeycloakRedhat Single Sign-on | 13/11/2018 | 17/6/2026 | A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures. | |
| Modificada | Media (5.4) | 1.2% | — | Redhat KeycloakRedhat Single Sign-on | 13/11/2018 | 17/6/2026 | A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Security Access Manager FOR Enterprise Single Sign-on | 17/8/2018 | 17/6/2026 | IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure… | |
| Modificada | Media (5.4) | 0.35% | — | Redhat KeycloakRedhat Single Sign-on | 1/8/2018 | 17/6/2026 | It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks. | |
| Modificada | Media (4.9) | 1.3% | — | Redhat KeycloakRedhat Single Sign-on | 23/7/2018 | 17/6/2026 | keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server. | |
| Modificada | Media (5.9) | 2.0% | — | Redhat KeycloakRedhat Single Sign ON | 12/3/2018 | 17/6/2026 | Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks. | |
| Modificada | Media (6.5) | 1.9% | — | Redhat KeycloakRedhat Single Sign ON | 12/3/2018 | 17/6/2026 | Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm. | |
| Modificada | Media (6.1) | 0.88% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 27/11/2017 | 17/6/2026 | In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks. | |
| Modificada | Alta (7.5) | 2.7% | — | Redhat Single Sign ONKeycloak | 26/10/2017 | 17/6/2026 | It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks. | |
| Modificada | Media (5.4) | 1.0% | — | Redhat Single Sign ONKeycloak | 26/10/2017 | 17/6/2026 | It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server. | |
| Modificada | Media (6.1) | 0.88% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 9/9/2017 | 17/6/2026 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name. | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 9/9/2017 | 17/6/2026 | In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed XML leading to exposure of data on the Single Sign-On… |