VendorsApachejuddiany version
Vulnerabilities

Apache Software Foundation jUDDI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-37578
Remote code execution via RMI
Published 2021-07-29 · Modified
9.8EPSS 0.041
CVE-2018-1307
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.
Published 2018-02-09 · Modified
8.1EPSS 0.017
CVE-2009-1198
Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname parameter to happyjuddi.jsp.
Published 2017-10-30 · Modified
6.1EPSS 0.048