Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ranger MEDIUM 6.5
CVE-2016-6815

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

Mitigation only
Fix from $1,600 2017-10-13
Nifi MEDIUM 6.5
CVE-2017-12623

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…

Mitigation only
Fix from $1,600 2017-10-10
Zookeeper HIGH 7.5
CVE-2017-5637EPSS 73%

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which lead…

Mitigation only
Fix from $1,950 2017-10-10
Roller CRITICAL 9.8
CVE-2014-0030EPSS 17%

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

No fix yet
Fix from $2,300 2017-10-10
Impala MEDIUM 6.5
CVE-2017-9792

In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt…

Mitigation only
Fix from $1,600 2017-10-04
Opennlp CRITICAL 9.8
CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…

No fix yet
Fix from $2,300 2017-10-03
Wicket HIGH 8.8
CVE-2016-6806

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …

Mitigation only
Fix from $1,950 2017-10-03
Wicket MEDIUM 5.3
CVE-2014-0043

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…

Mitigation only
Fix from $1,600 2017-10-03
Tika HIGH 7.8
CVE-2016-4434

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…

Mitigation only
Fix from $1,950 2017-09-30
Struts CRITICAL 9.8
CVE-2016-6795EPSS 8%

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…

Mitigation only
Fix from $2,300 2017-09-20
Tomcat HIGH 7.5
CVE-2017-12616EPSS 71%

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs …

Mitigation only
Fix from $1,950 2017-09-19
Solr HIGH 7.5
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a…

Mitigation only
Fix from $1,950 2017-09-18
Traffic Server CRITICAL 9.8
CVE-2015-5168

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a dif…

No fix yet
Fix from $2,300 2017-09-13
Traffic Server CRITICAL 9.8
CVE-2015-5206

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors…

Mitigation only
Fix from $2,300 2017-09-13
Spark HIGH 7.8
CVE-2017-12612

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …

Mitigation only
Fix from $1,950 2017-09-13
Hadoop CRITICAL 9.8
CVE-2016-3086

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…

Mitigation only
Fix from $2,300 2017-09-05
Ofbiz HIGH 8.8
CVE-2016-4462

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar…

Mitigation only
Fix from $1,950 2017-08-30
Ofbiz MEDIUM 6.1
CVE-2016-6800

The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to s…

Mitigation only
Fix from $1,600 2017-08-30
Atlas HIGH 7.5
CVE-2016-8752

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…

Mitigation only
Fix from $1,950 2017-08-29
Atlas HIGH 7.5
CVE-2017-3154

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

Mitigation only
Fix from $1,950 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3150

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3151

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3152

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3153

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3155

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

Mitigation only
Fix from $1,600 2017-08-29
Struts HIGH 7.5
CVE-2015-5209EPSS 9%

Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto…

Mitigation only
Fix from $1,950 2017-08-29
Tomcat HIGH 7.5
CVE-2017-7675EPSS 10%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory tr…

Mitigation only
Fix from $1,950 2017-08-11
Tomcat HIGH 7.5
CVE-2016-6817EPSS 7%

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger …

Mitigation only
Fix from $1,950 2017-08-10
Tomcat HIGH 7.5
CVE-2016-8745EPSS 16%

A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0…

Mitigation only
Fix from $1,950 2017-08-10
Storm HIGH 8.8
CVE-2017-9799

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for …

Mitigation only
Fix from $1,950 2017-08-09