Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ambari CRITICAL 9.8
CVE-2017-5642

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

Mitigation only
Fix from $2,300 2017-04-03
Ambari CRITICAL 9.8
CVE-2014-3582

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…

Fix: after 2.2.2
Fix from $2,300 2017-03-29
Ambari MEDIUM 5.5
CVE-2016-4976

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…

Mitigation only
Fix from $1,600 2017-03-29
Ambari CRITICAL 9.8
CVE-2016-6807

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …

Mitigation only
Fix from $2,300 2017-03-28
Camel CRITICAL 9.8
CVE-2016-8749EPSS 11%

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

No fix yet
Fix from $2,300 2017-03-28
Poi MEDIUM 5.5
CVE-2017-5644

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML fil…

Fix: after 3.14
Fix from $1,600 2017-03-24
Hadoop MEDIUM 6.5
CVE-2014-0229

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…

Mitigation only
Fix from $1,600 2017-03-23
Tomcat HIGH 7.1
CVE-2016-6816EPSS 40%

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque…

No fix yet
Fix from $1,950 2017-03-20
Camel HIGH 7.4
CVE-2017-5643EPSS 6%

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Fix: after 2.16.0
Fix from $1,950 2017-03-16
Tomcat HIGH 7.5
CVE-2016-8747EPSS 7%

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu…

Fix: 8.5.10+
Fix from $1,950 2017-03-14
Struts CRITICAL 9.8
CVE-2017-5638 KEVEPSS 100%

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message gene…

Fix: 2.3.32 / 2.5.10.1+
Fix from $2,300 2017-03-11
Camel CRITICAL 9.8
CVE-2017-3159EPSS 6%

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur…

Fix: after 2.18.1
Fix from $2,300 2017-03-07
Guacamole MEDIUM 5.4
CVE-2016-1566

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by mult…

Mitigation only
Fix from $1,600 2017-02-02
Groovy Ldap HIGH 7.5
CVE-2016-6497EPSS 6%

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leve…

Patch available
Fix from $1,950 2017-01-18
Storm CRITICAL 9.8
CVE-2015-3188EPSS 14%

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

No fix yet
Fix from $2,300 2017-01-13
Tika MEDIUM 5.3
CVE-2015-3271EPSS 7%

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

Mitigation only
Fix from $1,600 2016-12-15
HTTP Server HIGH 7.5
CVE-2016-8740EPSS 79%

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-…

Patch available
Fix from $1,950 2016-12-05
Hadoop HIGH 8.8
CVE-2016-5393

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm…

Mitigation only
Fix from $1,950 2016-11-29
Commons Fileupload CRITICAL 9.8
CVE-2016-1000031EPSS 34%

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Fix: after 1.3.2
Fix from $2,300 2016-10-25
Tomcat HIGH 7.8
CVE-2016-6325

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig…

Mitigation only
Fix from $1,950 2016-10-13
Tomcat HIGH 7.8
CVE-2016-5425

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions f…

No fix yet
Fix from $1,950 2016-10-13
Derby CRITICAL 9.1
CVE-2015-1832EPSS 12%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
Myfaces Trinidad CRITICAL 9.8
CVE-2016-5019EPSS 8%

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…

Fix: 1.0.13 / 1.2.15+
Fix from $2,300 2016-10-03
Struts CRITICAL 9.8
CVE-2016-4436EPSS 7%

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

Mitigation only
Fix from $2,300 2016-10-03
Tomcat HIGH 7.8
CVE-2016-1240EPSS 10%

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …

No fix yet
Fix from $1,950 2016-10-03
Artemis HIGH 7.2
CVE-2016-4978EPSS 7%

The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache Ac…

Fix: 1.4.0+
Fix from $1,950 2016-09-27
Cxf Fediz CRITICAL 9.8
CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…

Mitigation only
Fix from $2,300 2016-09-21
Jackrabbit HIGH 8.8
CVE-2016-6801

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be…

Mitigation only
Fix from $1,950 2016-09-21
Zookeeper HIGH 8.1
CVE-2016-5017EPSS 8%

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers…

Fix: after 3.4.8
Fix from $1,950 2016-09-21
Shiro HIGH 7.5
CVE-2016-6802EPSS 10%

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

No fix yet
Fix from $1,950 2016-09-20