VendorsRed Hatjboss_data_gridany version
Vulnerabilities

Red Hat Jboss Data Grid any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2019-14892
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Published 2020-03-02 · Modified
9.8EPSS 0.056
CVE-2019-3888
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
Published 2019-06-12 · Modified
9.8EPSS 0.030
CVE-2019-10212
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Published 2019-10-02 · Modified
9.8EPSS 0.019
CVE-2019-10174
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Published 2019-11-25 · Modified
8.8EPSS 0.031
CVE-2019-10184
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Published 2019-07-25 · Modified
7.5EPSS 0.035
CVE-2019-14888
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Published 2020-01-23 · Modified
7.5EPSS 0.021
CVE-2023-5384
Infinispan: credentials returned from configuration as clear text
Published 2023-12-18 · Modified
7.2EPSS 0.005
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2023-5236
Infinispan: circular reference on marshalling leads to dos
Published 2023-12-18 · Modified
6.5EPSS 0.009
CVE-2023-3628
Infispan: rest bulk ops don't check permissions
Published 2023-12-18 · Modified
6.5EPSS 0.008
CVE-2023-3629
Infinispan: non-admins should not be able to get cache config via rest api
Published 2023-12-18 · Modified
6.5EPSS 0.007
CVE-2020-1710
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Published 2020-09-16 · Modified
5.3EPSS 0.012