📦

jboss_enterprise_web_server

Vendor: redhat

Actively Exploited 3 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 7 Remote Access
Total CVEs 233 Total Indexed
Avg. EPSS 29.79% Exploit Prob.
Latest CVE CVE-2020-25710 May 28

Security Vulnerability Index

Page 1 / 24
7.5 CVSS

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

EPSS: 2.67%
7.5 CVSS

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

EPSS: 0.91%
7.5 CVSS

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

EPSS: 8.04%
8.1 CVSS

eDeploy has tmp file race condition flaws

EPSS: 1.50%
9.8 CVSS

eDeploy has RCE via cPickle deserialization of untrusted data

EPSS: 2.37%
3.3 CVSS

An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies

EPSS: 0.32%
9.8 CVSS

eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

EPSS: 2.84%
4.3 CVSS

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

EPSS: 0.46%
9.8 CVSS
CVE-2011-3923
RCE Exploit Found

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

EPSS: 88.83%
5.9 CVSS

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).

EPSS: 17.14%