Redhat
Redhat Jboss Enterprise WEB Server: vulnerabilidades y CVE
Redhat Jboss Enterprise WEB Server tiene 35 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses0
Críticas7
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
| CVE-2017-12615 | Alta (8.1) | 100% | ⚠ Explotación activa | 19 sept 2017 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-25710 | Alta (7.5) | 2.7% | — | 28 may 2021 | A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this… |
| CVE-2012-5626 | Alta (7.5) | 0.91% | — | 23 ene 2020 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss… |
| CVE-2019-19906 | Alta (7.5) | 8.0% | — | 19 dic 2019 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error… |
| CVE-2014-3701 | Alta (8.1) | 1.5% | — | 15 dic 2019 | eDeploy has tmp file race condition flaws |
| CVE-2014-3699 | Crítica (9.8) | 2.4% | — | 15 dic 2019 | eDeploy has RCE via cPickle deserialization of untrusted data |
| CVE-2012-2148 | Baja (3.3) | 0.32% | — | 6 dic 2019 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies |
| CVE-2014-3700 | Crítica (9.8) | 2.8% | — | 21 nov 2019 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
| CVE-2014-3655 | Media (4.3) | 0.46% | — | 13 nov 2019 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF |
| CVE-2011-3923 | Crítica (9.8) | 89% | — | 1 nov 2019 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. |
| CVE-2019-1559 | Media (5.9) | 17% | — | 27 feb 2019 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte… |
| CVE-2018-1336 | Alta (7.5) | 21% | — | 2 ago 2018 | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to… |
| CVE-2018-1304 | Media (5.9) | 17% | — | 28 feb 2018 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of… |
| CVE-2015-7501 | Crítica (9.8) | 86% | — | 9 nov 2017 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x;… |
| CVE-2017-12613 | Alta (7.1) | 1.7% | — | 24 oct 2017 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
| CVE-2015-5184 | Alta (7.5) | 1.2% | — | 25 sept 2017 | Console: CORS headers set to allow all in Red Hat AMQ. |
| CVE-2015-5183 | Alta (7.5) | 2.2% | — | 25 sept 2017 | Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. |
| CVE-2017-12615 | Alta (8.1) | 100% | ⚠ Explotación activa | 19 sept 2017 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a… |
| CVE-2016-6796 | Alta (7.5) | 8.3% | — | 11 ago 2017 | A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the… |
| CVE-2016-6797 | Alta (7.5) | 8.1% | — | 10 ago 2017 | The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to… |
| CVE-2016-6794 | Media (5.3) | 7.2% | — | 10 ago 2017 | When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0… |
| CVE-2016-5018 | Crítica (9.1) | 10% | — | 10 ago 2017 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method… |
| CVE-2016-0762 | Media (5.9) | 8.0% | — | 10 ago 2017 | The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not… |
| CVE-2017-9788 | Crítica (9.1) | 57% | — | 13 jul 2017 | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by… |
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
| CVE-2016-3110 | Alta (7.5) | 3.6% | — | 26 sept 2016 | mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate… |
| CVE-2016-2183 | Alta (7.5) | 95% | — | 1 sept 2016 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to… |
| CVE-2016-5387 | Alta (8.1) | 56% | — | 19 jul 2016 | The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow… |
| CVE-2014-0224 | Alta (7.4) | 95% | — | 5 jun 2014 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master… |
| CVE-2013-5704 | Media (5) | 53% | — | 15 abr 2014 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230