VendorsRed Hatjboss_enterprise_application_platform6.0.0
Vulnerabilities

Red Hat JBoss Enterprise Application Platform 4.2.0 CP09 6.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2012-4572
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
Published 2013-10-28 · Modified
3.7EPSS 0.003
CVE-2014-0058
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
Published 2014-02-26 · Modified
1.9EPSS 0.003
CVE-2013-1921
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
Published 2013-09-28 · Modified
1.9EPSS 0.002
← Prev2 / 2