VendorsRed Hatjboss_middlewareall versions
Vulnerabilities

Red Hat JBoss Middleware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-4853
Quarkus: http security policy bypass
Published 2023-09-20 · Modified
8.1EPSS 0.014
CVE-2016-3674
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
Published 2016-05-17 · Analyzed
7.5EPSS 0.082
CVE-2017-7957
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
Published 2017-04-29 · Analyzed
7.5EPSS 0.049
CVE-2018-1304
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Published 2018-02-28 · Modified
5.9EPSS 0.171
CVE-2023-4065
Operator: plaintext password in operator log
Published 2023-09-26 · Modified
5.5EPSS 0.002
CVE-2023-4066
Operator: passwords defined in secrets shown in statefulset yaml
Published 2023-09-27 · Modified
5.5EPSS 0.002