Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
523 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.0% | — | Redhat Jboss Portal | 2/1/2020 | 17/6/2026 | It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information… | |
| Modificada | Media (6.5) | 0.78% | — | Redhat Jboss Enterprise Application Platform | 2/1/2020 | 17/6/2026 | In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality,… | |
| Modificada | Crítica (9.8) | 2.0% | — | InfinispanRedhat Jboss Data Grid | 2/1/2020 | 17/6/2026 | A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Alta (7.8) | 0.29% | — | Redhat Jboss Application ServerRedhat Jboss Enterprise Application Platform | 18/12/2019 | 16/6/2026 | An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges. | |
| Modificada | Alta (8.1) | 1.5% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has tmp file race condition flaws | |
| Modificada | Crítica (9.8) | 2.4% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has RCE via cPickle deserialization of untrusted data | |
| Modificada | Media (6.1) | 0.65% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Portal | 11/12/2019 | 17/6/2026 | JBossWeb Bayeux has reflected XSS | |
| Modificada | Media (6.1) | 0.77% | 💥 PoC | Redhat Jboss Keycloak | 10/12/2019 | 17/6/2026 | JBoss KeyCloak: XSS in login-status-iframe.html | |
| Modificada | Baja (3.3) | 0.32% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server | 6/12/2019 | 16/6/2026 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a… | |
| Modificada | Media (5.4) | 1.1% | — | Redhat Jboss Application Server | 26/11/2019 | 16/6/2026 | A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment… | |
| Modificada | Alta (8.8) | 3.1% | — | InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+3 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | |
| Modificada | Crítica (9.8) | 2.8% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 21/11/2019 | 17/6/2026 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | |
| Modificada | Alta (7.5) | 17% | 💥 PoC | Fasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+1 | 18/11/2019 | 17/6/2026 | A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. | |
| Modificada | Media (4.3) | 0.46% | — | Redhat KeycloakRedhat Jboss Enterprise WEB Server | 13/11/2019 | 17/6/2026 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF | |
| Modificada | Media (6.1) | 0.85% | — | Redhat Jboss Business Rules Management System | 12/11/2019 | 16/6/2026 | JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (6.5) | 0.87% | — | Redhat Jboss Operations Network | 8/11/2019 | 16/6/2026 | In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat RHQ Mongo DB Drift ServerRedhat Jboss Operations Network | 4/11/2019 | 16/6/2026 | An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files. | |
| Modificada | Media (6.1) | 0.65% | — | Redhat Jboss Aerogear | 4/11/2019 | 17/6/2026 | JBoss AeroGear has reflected XSS via the password field | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | Apache StrutsRedhat Jboss Enterprise WEB Server | 1/11/2019 | 16/6/2026 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | |
| Modificada | Alta (8) | 0.53% | — | Redhat Jboss Operations Network | 30/10/2019 | 16/6/2026 | A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user. | |
| Modificada | Alta (7.5) | 6.4% | — | Apache ThriftRedhat Jboss Enterprise Application PlatformOracle Communications Cloud Native Core Network Slice Selection Function | 29/10/2019 | 17/6/2026 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. |