VendorsRed Hatprocess_automationall versions
Vulnerabilities

Red Hat Process Automation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2019-14892
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Published 2020-03-02 · Modified
9.8EPSS 0.056
CVE-2025-12543
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
Published 2026-01-07 · Modified
9.6EPSS 0.014
CVE-2026-28367
Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28369
Undertow: undertow: request smuggling via malformed http request headers
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28368
Undertow: undertow: request smuggling via inconsistent header parsing
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2020-1714
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
Published 2020-05-13 · Modified
8.8EPSS 0.026
CVE-2022-1415
Drools: unsafe data deserialization in streamutils
Published 2023-09-11 · Modified
8.8EPSS 0.010
CVE-2019-14841
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Published 2022-10-17 · Modified
8.8EPSS 0.007
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2021-4104
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
Published 2021-12-14 · Modified
7.5EPSS 0.806
CVE-2024-7885
Undertow: improper state management in proxy protocol parsing causes information leakage
Published 2024-08-21 · Modified
7.5EPSS 0.026
CVE-2025-9784
Undertow: undertow madeyoureset http/2 ddos vulnerability
Published 2025-09-02 · Modified
7.5EPSS 0.023
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2020-10714
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-09-23 · Modified
7.5EPSS 0.015
CVE-2022-0853
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
Published 2022-03-11 · Modified
7.5EPSS 0.015
CVE-2020-1748
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.
Published 2020-09-16 · Modified
7.5EPSS 0.014
CVE-2019-14839
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
Published 2022-04-01 · Modified
7.5EPSS 0.010
CVE-2021-20218
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Published 2021-03-16 · Modified
7.4EPSS 0.013
CVE-2019-14863
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Published 2020-01-02 · Modified
7.1EPSS 0.012
CVE-2021-4178
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
Published 2022-08-24 · Modified
6.7EPSS 0.003
CVE-2019-14862
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Published 2020-01-02 · Modified
6.1EPSS 0.021
CVE-2021-3642
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Published 2021-08-05 · Modified
5.3EPSS 0.008
CVE-2021-20306
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality.
Published 2021-06-01 · Modified
4.3EPSS 0.007