Redhat
Redhat Wildfly: vulnerabilidades y CVE
Redhat Wildfly tiene 19 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81624 | Alta (7.5) | 0.58% | — | 31 ago 2026 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and… |
| CVE-2025-23367 | Media (6.5) | 0.77% | — | 30 ene 2025 | A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required… |
| CVE-2022-1278 | Alta (7.5) | 0.86% | — | 13 sept 2022 | A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. |
| CVE-2021-3644 | Baja (3.3) | 0.96% | — | 26 ago 2022 | A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially… |
| CVE-2022-0866 | Media (5.3) | 0.90% | — | 10 may 2022 | This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the… |
| CVE-2021-3503 | Media (4.3) | 1.1% | — | 18 abr 2022 | A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality. |
| CVE-2020-1719 | Media (5.4) | 0.57% | — | 7 jun 2021 | A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity.… |
| CVE-2020-14317 | Media (5.5) | 0.19% | — | 2 jun 2021 | It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit… |
| CVE-2021-3536 | Media (4.8) | 0.53% | — | 20 may 2021 | A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality… |
| CVE-2020-27822 | Media (5.9) | 1.1% | — | 8 dic 2020 | A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a… |
| CVE-2020-25640 | Media (5.3) | 1.3% | — | 24 nov 2020 | A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file. |
| CVE-2020-25689 | Media (6.5) | 1.5% | — | 2 nov 2020 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to… |
| CVE-2020-10718 | Alta (7.5) | 1.4% | — | 16 sept 2020 | A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which… |
| CVE-2020-10740 | Alta (7.5) | 2.1% | — | 22 jun 2020 | A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in… |
| CVE-2019-14887 | Crítica (9.1) | 1.1% | — | 16 mar 2020 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the… |
| CVE-2019-3894 | Alta (8.8) | 1.5% | — | 3 may 2019 | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time… |
| CVE-2019-3805 | Media (4.7) | 0.19% | — | 3 may 2019 | A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying… |
| CVE-2018-14627 | Media (5.9) | 1.1% | — | 4 sept 2018 | The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to… |
| CVE-2018-10683 | Crítica (9.8) | 1.8% | — | 9 may 2018 | An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms… |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230