VendorsRed Hatjboss_community_application_serverall versions
Vulnerabilities

Red Hat JBoss Community Application Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2012-4529
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
Published 2013-10-28 · Modified
4.3EPSS 0.020
CVE-2012-2148
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
Published 2019-12-06 · Modified
3.3EPSS 0.003
CVE-2009-5066
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
Published 2012-08-13 · Modified
2.1EPSS 0.004