Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Juddi MEDIUM 6.1
CVE-2015-5241

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…

Mitigation only
Fix from $1,600 2017-05-19
Qpid Broker J HIGH 7.5
CVE-2016-8741EPSS 6%

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices…

Mitigation only
Fix from $1,950 2017-05-15
Ambari MEDIUM 6.5
CVE-2017-5655

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file…

Mitigation only
Fix from $1,600 2017-05-15
Ambari HIGH 7.5
CVE-2017-5654

In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on …

Mitigation only
Fix from $1,950 2017-05-12
Qpid Proton MEDIUM 5.9
CVE-2016-4467

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m…

Mitigation only
Fix from $1,600 2017-05-02
Tomcat CRITICAL 9.1
CVE-2017-5648EPSS 13%

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0…

Mitigation only
Fix from $2,300 2017-04-17
Tomcat HIGH 7.5
CVE-2017-5647EPSS 17%

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…

Mitigation only
Fix from $1,950 2017-04-17
Tomcat HIGH 7.5
CVE-2017-5650EPSS 8%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated …

Mitigation only
Fix from $1,950 2017-04-17
Ambari CRITICAL 9.8
CVE-2017-5642

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

Mitigation only
Fix from $2,300 2017-04-03
Ambari MEDIUM 5.5
CVE-2016-4976

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…

Mitigation only
Fix from $1,600 2017-03-29
Ambari CRITICAL 9.8
CVE-2016-6807

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …

Mitigation only
Fix from $2,300 2017-03-28
Camel CRITICAL 9.8
CVE-2016-8749EPSS 11%

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

No fix yet
Fix from $2,300 2017-03-28
Hadoop MEDIUM 6.5
CVE-2014-0229

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…

Mitigation only
Fix from $1,600 2017-03-23
Tomcat HIGH 7.1
CVE-2016-6816EPSS 40%

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque…

No fix yet
Fix from $1,950 2017-03-20
Guacamole MEDIUM 5.4
CVE-2016-1566

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by mult…

Mitigation only
Fix from $1,600 2017-02-02
Storm CRITICAL 9.8
CVE-2015-3188EPSS 14%

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

No fix yet
Fix from $2,300 2017-01-13
Tika MEDIUM 5.3
CVE-2015-3271EPSS 7%

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

Mitigation only
Fix from $1,600 2016-12-15
Hadoop HIGH 8.8
CVE-2016-5393

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm…

Mitigation only
Fix from $1,950 2016-11-29
Tomcat HIGH 7.8
CVE-2016-6325

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig…

Mitigation only
Fix from $1,950 2016-10-13
Tomcat HIGH 7.8
CVE-2016-5425

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions f…

No fix yet
Fix from $1,950 2016-10-13
Derby CRITICAL 9.1
CVE-2015-1832EPSS 12%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
Struts CRITICAL 9.8
CVE-2016-4436EPSS 7%

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

Mitigation only
Fix from $2,300 2016-10-03
Tomcat HIGH 7.8
CVE-2016-1240EPSS 10%

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …

No fix yet
Fix from $1,950 2016-10-03
Cxf Fediz CRITICAL 9.8
CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…

Mitigation only
Fix from $2,300 2016-09-21
Jackrabbit HIGH 8.8
CVE-2016-6801

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be…

Mitigation only
Fix from $1,950 2016-09-21
Shiro HIGH 7.5
CVE-2016-6802EPSS 10%

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

No fix yet
Fix from $1,950 2016-09-20
Sentry HIGH 8.8
CVE-2016-0760

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…

Mitigation only
Fix from $1,950 2016-08-19
Activemq MEDIUM 5.4
CVE-2016-0782EPSS 6%

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users…

No fix yet
Fix from $1,600 2016-08-05
Struts MEDIUM 5.3
CVE-2016-4465EPSS 10%

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…

Mitigation only
Fix from $1,600 2016-07-04
Struts CRITICAL 9.8
CVE-2016-4438EPSS 17%

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation only
Fix from $2,300 2016-07-04