Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

446 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)7.5%—Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+82/1/201917/6/2026
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
ModificadaAlta (7.5)91%💥 ExploitApache Tomcat JK ConnectorDebian LinuxRedhat Jboss Core Services31/10/201817/6/2026
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a…
ModificadaMedia (5.4)1.7%—Redhat Jboss BPM Suite31/10/201817/6/2026
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within…
ModificadaMedia (5.3)2.1%—Redhat UndertowRedhat Jboss Enterprise Application Platform18/9/201817/6/2026
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
ModificadaAlta (7.8)0.30%—Redhat Jboss Enterprise Application Platform11/9/201817/6/2026
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
ModificadaMedia (6.5)1.8%—Redhat Jboss Enterprise Application Platform10/9/201817/6/2026
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.
ModificadaMedia (6.5)4.0%—Redhat Jboss BrmsRedhat Jboss Drools10/9/201817/6/2026
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.
ModificadaAlta (7.5)6.6%—Dom4j Project Dom4jDebian LinuxOracle Flexcube Investor ServicingOracle Primavera P6 Enterprise Project Portfolio Management+1020/8/201817/6/2026
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML…
ModificadaMedia (6.5)1.2%—Redhat Jboss Core ServicesXmlsoft Libxml216/8/201817/6/2026
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML document. NOTE: this vulnerability exists because of a missing fix for CVE-2016-4483.
ModificadaMedia (6.5)1.1%—Redhat Jboss Core ServicesXmlsoft Libxml216/8/201817/6/2026
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-3627.
ModificadaAlta (7.5)20%—Apache TomcatRedhat Jboss Enterprise Application PlatformCanonical Ubuntu LinuxDebian Linux+42/8/201817/6/2026
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
ModificadaMedia (5.3)1.9%—Redhat Jboss A-mqRedhat Jboss Fuse1/8/201817/6/2026
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
ModificadaAlta (7.2)2.0%—Redhat Jboss A-mqRedhat Jboss Fuse1/8/201817/6/2026
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization…
ModificadaMedia (5.4)1.3%—Redhat Jboss BPM SuiteRedhat Jboss Business Rules Management System1/8/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users,…
ModificadaAlta (7.8)0.42%—Redhat Jboss Enterprise Application Platform31/7/201817/6/2026
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the…
ModificadaMedia (6.1)1.8%—Redhat Jboss BPM Suite27/7/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the…
ModificadaMedia (5.4)1.3%—Redhat Jboss BPM Suite27/7/201817/6/2026
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized…
ModificadaMedia (6.5)1.5%—Redhat Jboss BPM SuiteRedhat Jboss Data Virtualization & Services27/7/201817/6/2026
It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing…
ModificadaAlta (7.5)3.6%—Redhat UndertowDebian LinuxRedhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
ModificadaMedia (6.5)3.1%—Redhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
ModificadaAlta (7.5)1.9%—Redhat UndertowRedhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
ModificadaMedia (5.5)1.3%—Redhat VirtualizationRedhat Jboss Enterprise Application PlatformRedhat Wildfly Core27/7/201817/6/2026
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.
ModificadaMedia (6.5)3.1%💥 PoCRedhat UndertowRedhat Jboss Enterprise Application PlatformDebian Linux27/7/201817/6/2026
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the…
ModificadaCrítica (9.8)1.9%—Redhat Jboss Enterprise Application Platform27/7/201817/6/2026
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.
ModificadaMedia (6.5)2.4%—Redhat KeycloakRedhat Jboss Enterprise Application Platform26/7/201817/6/2026
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be…
Orbitaley — Vulnerabilidades