Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

258 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.0%—Redhat Jboss Enterprise Application Platform7/7/201417/6/2026
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
ModificadaMedia (6.8)3.5%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss WEB Framework KIT7/7/201417/6/2026
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
ModificadaMedia (4.3)7.1%—Apache CXFRedhat Jboss Enterprise Application Platform7/7/201417/6/2026
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (4.3)7.4%—Apache CXFRedhat Jboss Enterprise Application Platform7/7/201417/6/2026
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
ModificadaAlta (7.4)95%💥 PoCOpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+125/6/201417/6/2026
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive…
ModificadaMedia (5.8)2.1%—Redhat Jboss Enterprise Application Platform3/4/201417/6/2026
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
ModificadaBaja (1.9)0.35%—Redhat Jboss Enterprise Application Platform26/2/201417/6/2026
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
ModificadaBaja (1.9)0.35%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Wildfly Application Server14/2/201417/6/2026
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.
ModificadaMedia (5)2.2%—Redhat Jboss Communications PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise WEB Platform10/2/201416/6/2026
JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character"…
ModificadaBaja (2.1)0.35%—Redhat Jboss Enterprise Application Platform2/2/201416/6/2026
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
ModificadaAlta (7.5)7.2%—Apache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal Platform19/1/201416/6/2026
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186.…
ModificadaMedia (5.5)1.8%—Redhat Jboss Enterprise Application PlatformRedhat Enterprise Linux6/12/201316/6/2026
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging…
ModificadaBaja (3.7)0.34%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal Platform28/10/201316/6/2026
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications'…
ModificadaMedia (4.3)2.0%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform28/10/201316/6/2026
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a…
ModificadaMedia (5)2.7%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise SOA PlatformRedhat Jboss Enterprise WEB Platform1/10/201316/6/2026
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.
ModificadaMedia (5.4)1.6%—Jgroups JgroupRedhat Jboss Enterprise Application Platform28/9/201316/6/2026
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
ModificadaBaja (1.9)0.24%—Redhat Jboss Enterprise Application Platform28/9/201316/6/2026
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
ModificadaMedia (6.4)6.3%💥 PoCApache CXFRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+219/8/201316/6/2026
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended…
ModificadaMedia (6.4)2.5%—Redhat Jboss Enterprise Application Platform16/8/201316/6/2026
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
ModificadaMedia (6.4)2.5%—Redhat Jboss Enterprise Application Platform16/8/201316/6/2026
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
ModificadaMedia (5)2.7%—Redhat Jboss Communications PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal Platform+329/7/201316/6/2026
wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0;…
ModificadaAlta (7.5)13%💥 PoCRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise SOA Platform+423/7/201316/6/2026
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform…
ModificadaMedia (4.3)29%—Apache Http ServerRedhat Jboss Enterprise Application PlatformRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+510/7/201316/6/2026
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML…
ModificadaMedia (5.1)25%—Apache Http ServerRedhat Jboss Enterprise Application PlatformOracle Http ServerRedhat Enterprise Linux Desktop+610/6/201316/6/2026
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
ModificadaAlta (7.5)2.3%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Platform12/3/201316/6/2026
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.