« Back to list

Redhat

Redhat Jboss WEB Server: vulnerabilities and CVEs

Redhat Jboss WEB Server has 4 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.

CVEs4
Last 12 months1
Critical0
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-34486High (7.5)6.6%⚠ Active exploitationApr 9, 2026
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-34486High (7.5)6.6%⚠ Active exploitationApr 9, 2026
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are…
CVE-2021-4104High (7.5)81%—Dec 14, 2021
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName…
CVE-2016-2183High (7.5)95%—Sep 1, 2016
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to…
CVE-2016-5387High (8.1)56%—Jul 19, 2016
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Redhat