Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Application Platform HIGH 7.5
CVE-2016-2094

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshak…

Mitigation only
Fix from $1,950 2016-05-06
Enterprise Application Platform MEDIUM 5.0
CVE-2008-3273EPSS 47%

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensiti…

Fix: after 4.3.0
Fix from $1,600 2008-08-10
Seam HIGH 7.5
CVE-2007-6433

The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and exec…

Fix: after 2.0.0
Fix from $1,950 2007-12-18
Jboss Application Server MEDIUM 6.0
CVE-2007-1354

The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member…

Patch available
Fix from $1,600 2007-07-27
Jboss HIGH 7.6
CVE-2007-1157

Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administ…

Mitigation only
Fix from $1,950 2007-03-02
Jboss Application Server HIGH 7.5
CVE-2007-1036EPSS 82%

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to by…

Mitigation only
Fix from $1,950 2007-02-21
Jboss Application Server HIGH 7.5
CVE-2006-5750EPSS 14%

Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authe…

Patch available
Fix from $1,950 2006-11-27
Jbpm HIGH 7.5
CVE-2005-2158

A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerabilit…

Patch available
Fix from $1,950 2005-07-06
Jboss MEDIUM 5.0
CVE-2005-2006EPSS 9%

JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which re…

Mitigation only
Fix from $1,600 2005-06-17
Jboss HIGH 7.5
CVE-2003-0845EPSS 15%

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows rem…

Patch available
Fix from $1,950 2003-11-17