Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Qpid MEDIUM 6.8
CVE-2012-4446

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t…

Fix: after 0.20
Fix from $1,600 2013-03-14
Cxf MEDIUM 5.8
CVE-2012-5633EPSS 8%

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu…

Fix: after 2.5.7
Fix from $1,600 2013-03-12
Cxf MEDIUM 5.0
CVE-2013-0239

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att…

Fix: after 2.5.8
Fix from $1,600 2013-03-12
Tomcat MEDIUM 5.0
CVE-2012-5886EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5887EPSS 12%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly…

Fix: 5.5.36 / 6.0.36+
Fix from $1,600 2012-11-17
Axis2 MEDIUM 6.4
CVE-2012-5351EPSS 5%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…

Mitigation only
Fix from $1,600 2012-10-09
Axis2 MEDIUM 5.8
CVE-2012-4418EPSS 6%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

No fix yet
Fix from $1,600 2012-10-09
Qpid MEDIUM 5.0
CVE-2012-3467EPSS 6%

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo…

Fix: after 0.16
Fix from $1,600 2012-08-27
Qpid HIGH 7.5
CVE-2011-3620EPSS 5%

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…

Mitigation only
Fix from $1,950 2012-05-03
Geronimo HIGH 7.5
CVE-2007-5797

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…

Mitigation only
Fix from $1,950 2007-11-03
Geronimo MEDIUM 5.0
CVE-2007-5085

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…

Mitigation only
Fix from $1,600 2007-09-26
Geronimo HIGH 10.0
CVE-2007-4548

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…

Patch available
Fix from $1,950 2007-08-27