VendorsRed Hatjboss_enterprise_application_platform_text-only_advisoriesall versions
Vulnerabilities

Red Hat JBoss Enterprise Application Platform Text-only Advisories

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-7238
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
Published 2020-01-27 · Modified
7.5EPSS 0.036
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2011-2487
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
Published 2020-03-11 · Modified
5.9EPSS 0.018