VendorsRed Hatjboss_enterprise_application_platform6
Vulnerabilities

Red Hat JBoss Enterprise Application Platform 4.2.0 CP09 6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-3628
Infispan: rest bulk ops don't check permissions
Published 2023-12-18 · Modified
6.5EPSS 0.008
CVE-2023-3629
Infinispan: non-admins should not be able to get cache config via rest api
Published 2023-12-18 · Modified
6.5EPSS 0.007
CVE-2018-1304
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Published 2018-02-28 · Modified
5.9EPSS 0.171