Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Redhat Jboss FuseRedhat Wildfly16/9/202017/6/2026
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality.
ModificadaMedia (5.3)1.2%—Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Single Sign-on16/9/202017/6/2026
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
ModificadaAlta (7.5)1.4%—Redhat Jboss Enterprise Application PlatformRedhat Jbossweb9/9/202017/6/2026
A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system…
ModificadaMedia (6.5)1.2%—Redhat AMQRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss FuseRedhat Openshift Application Runtimes+124/7/202017/6/2026
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service…
ModificadaMedia (6.5)1.2%—Redhat AMQRedhat Jboss-ejb-clientRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss Fuse+224/7/202017/6/2026
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services…
ModificadaMedia (6.5)2.1%💥 PoCHibernate ORMRedhat Build OF QuarkusRedhat Decision ManagerRedhat Fuse+66/7/202017/6/2026
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or…
ModificadaAlta (7.5)1.2%—Redhat UndertowNetapp Oncommand InsightRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes10/6/202017/6/2026
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
ModificadaMedia (6.5)0.98%—Redhat UndertowNetapp Oncommand InsightRedhat FuseRedhat Jboss Enterprise Application Platform+426/5/202017/6/2026
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
ModificadaAlta (8.8)2.6%—Redhat KeycloakRedhat Decision ManagerRedhat Jboss FuseRedhat Openshift Application Runtimes+313/5/202017/6/2026
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
ModificadaAlta (8.8)1.0%—Redhat Jboss FuseRedhat KeycloakRedhat Openshift Application Runtimes12/5/202017/6/2026
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
ModificadaMedia (5.3)2.4%—Redhat Hibernate ValidatorIBM Websphere Application ServerRedhat Jboss Enterprise Application PlatformRedhat Satellite+36/5/202017/6/2026
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling…
ModificadaMedia (4.2)0.66%—Redhat SoteriaRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Openshift Application Runtimes4/5/202017/6/2026
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
ModificadaAlta (8.1)1.6%—Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+221/4/202017/6/2026
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping…
ModificadaCrítica (9.1)1.1%—Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+216/3/202017/6/2026
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a…
ModificadaMedia (5.9)1.8%—Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+611/3/202016/6/2026
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
ModificadaAlta (7.5)1.1%—Redhat Jboss Application Server10/3/202016/6/2026
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
ModificadaCrítica (9.8)5.6%—Fasterxml Jackson-databindRedhat Decision ManagerRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+42/3/202017/6/2026
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
ModificadaCrítica (9.1)13%—NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+329/1/202017/6/2026
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
ModificadaCrítica (9.1)8.9%—NettyDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+229/1/202017/6/2026
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
ModificadaAlta (7.5)3.6%—NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+227/1/202017/6/2026
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
ModificadaMedia (4.3)0.74%—Redhat Jboss Enterprise Application PlatformRedhat Single Sign-on23/1/202017/6/2026
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.
ModificadaAlta (7.5)0.91%—Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+223/1/202016/6/2026
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
ModificadaAlta (7.5)2.1%—Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+223/1/202017/6/2026
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
ModificadaMedia (4.3)0.72%—Redhat KeycloakRedhat Single Sign-onRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse8/1/202017/6/2026
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
ModificadaAlta (8.8)1.2%—Redhat Single Sign-onRedhat Jboss Enterprise Application Platform7/1/202017/6/2026
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7…