Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.32%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server6/12/201916/6/2026
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
ModificadaMedia (4.3)2.0%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform28/10/201316/6/2026
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a…
ModificadaBaja (2.1)0.39%—Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform13/8/201216/6/2026
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.