Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.8 CVE-2012-4446 The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t… Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 5.8 CVE-2012-5633EPSS 8% The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu… Cxf after 2.5.7 Fix from $1,6002013-03-12 MEDIUM 5.0 CVE-2013-0239 Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att… Cxf after 2.5.8 Fix from $1,6002013-03-12 MEDIUM 5.0 CVE-2012-5886EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5887EPSS 12% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly… Tomcat 5.5.36 / 6.0.36+ Fix from $1,6002012-11-17 MEDIUM 6.4 CVE-2012-5351EPSS 5% Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur… Axis2 Mitigation only Fix from $1,6002012-10-09 MEDIUM 5.8 CVE-2012-4418EPSS 6% Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." Axis2 No fix yet Fix from $1,6002012-10-09 MEDIUM 5.0 CVE-2012-3467EPSS 6% Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo… Qpid after 0.16 Fix from $1,6002012-08-27 HIGH 7.5 CVE-2011-3620EPSS 5% Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin… Qpid Mitigation only Fix from $1,9502012-05-03 HIGH 7.5 CVE-2007-5797 SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut… Geronimo Mitigation only Fix from $1,9502007-11-03 MEDIUM 5.0 CVE-2007-5085 Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a… Geronimo Mitigation only Fix from $1,6002007-09-26 HIGH 10.0 CVE-2007-4548 The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att… Geronimo Patch available Fix from $1,9502007-08-27