Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Openshift Ai HIGH 7.8
CVE-2026-1462

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…

Fix: 2.25.7+
Fix from $1,950 2026-04-13
Mirror Registry For Red Hat Openshift HIGH 8.8
CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…

Mitigation only
Fix from $1,950 2026-04-08
Decision Manager HIGH 8.8
CVE-2022-1415

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a…

Mitigation only
Fix from $1,950 2023-09-11
Openshift HIGH 8.1
CVE-2021-4125

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…

Fix: 4.6.52 / 4.7.40+
Fix from $1,950 2022-08-24
Fabric8 Kubernetes MEDIUM 6.7
CVE-2021-4178

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure…

Fix: 5.0.3 / 5.1.2+
Fix from $1,600 2022-08-24
Jboss Enterprise Application Platform HIGH 7.2
CVE-2021-20318

The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary …

Mitigation only
Fix from $1,950 2021-12-23
Satellite MEDIUM 6.6
CVE-2021-42550

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configurat…

Fix: 1.0.3+
Fix from $1,600 2021-12-16
Fabric8 Maven HIGH 7.8
CVE-2020-10721

A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configur…

Fix: after 4.4.1
Fix from $1,950 2020-10-22
Wildfly HIGH 7.5
CVE-2020-10740

A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application…

Fix: 20.0.0+
Fix from $1,950 2020-06-22
Decision Manager CRITICAL 9.8
CVE-2019-14892EPSS 6%

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2020-03-02
Enterprise Linux HIGH 8.1
CVE-2020-2604

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…

Fix: after 13.0.1
Fix from $1,950 2020-01-15
Edeploy CRITICAL 9.8
CVE-2014-3699

eDeploy has RCE via cPickle deserialization of untrusted data

No fix yet
Fix from $2,300 2019-12-15
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2019-10202EPSS 5%

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…

Mitigation only
Fix from $2,300 2019-10-01
Openshift Container Platform CRITICAL 9.8
CVE-2018-11307EPSS 6%

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…

Fix: 2.6.7.3 / 2.7.9.4+
Fix from $2,300 2019-07-09
Virtualization Host HIGH 7.5
CVE-2018-10911

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read…

Fix: 3.12.14 / 4.1.8+
Fix from $1,950 2018-09-04
Jboss A Mq HIGH 7.2
CVE-2016-8648

It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX opera…

Mitigation only
Fix from $1,950 2018-08-01
Jboss A Mq MEDIUM 5.3
CVE-2016-8653

It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this …

Mitigation only
Fix from $1,600 2018-08-01
Jboss Data Grid HIGH 8.8
CVE-2018-1131

Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticat…

Mitigation only
Fix from $1,950 2018-05-15
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-9585

Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. …

Mitigation only
Fix from $1,600 2018-03-09
Resteasy HIGH 8.1
CVE-2018-1051

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…

Mitigation only
Fix from $1,950 2018-01-25
Data Grid CRITICAL 9.8
CVE-2015-7501EPSS 83%

Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Pl…

Mitigation only
Fix from $2,300 2017-11-09
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-7050

SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and R…

Mitigation only
Fix from $2,300 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2016-3690EPSS 5%

The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.

Mitigation only
Fix from $2,300 2017-06-08
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7504EPSS 29%

HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Se…

Fix: after 4.0
Fix from $2,300 2017-05-19
Satellite CRITICAL 9.8
CVE-2017-5929EPSS 8%

QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

Fix: 1.2.0+
Fix from $2,300 2017-03-13
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-7065EPSS 12%

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and pos…

No fix yet
Fix from $1,950 2016-10-13
Jboss Operations Network CRITICAL 9.8
CVE-2016-6330EPSS 11%

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote a…

Mitigation only
Fix from $2,300 2016-09-27
Openshift Container Platform CRITICAL 9.8
CVE-2015-8103EPSS 87%

The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized J…

Fix: 1.625.2 / 1.638+
Fix from $2,300 2015-11-25
System Config Firewall HIGH 7.8
CVE-2011-2520

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the bac…

Fix: after 1.2.29
Fix from $1,950 2011-07-21