V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

110 / 110
Product: redhat:jboss_fuse×Clear all
7.5
CVE-2023-44487ANC KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request ca…
2023-01-01MicrosoftKEV
EPSS100.0%
pct 100
9.8
CVE-2015-7501DEB
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtu…
2015-01-01Pre-auth
EPSS83.3%
pct 99
7.5
CVE-2021-4104DEB
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker h…
2021-01-01
EPSS81.1%
pct 99
5.9
CVE-2019-10172DEB
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entit…
2019-01-01Pre-auth
EPSS17.0%
pct 96
7.5
CVE-2019-14892DEB
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, wher…
2019-01-01Pre-auth
EPSS5.4%
pct 91
6.1
CVE-2016-1000229CVE
swagger-ui has XSS in key names
2016-01-01Pre-auth
EPSS4.0%
pct 89
9.8
CVE-2014-0121CVE
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to…
2014-01-01Pre-auth
EPSS3.9%
pct 88
7.5
CVE-2024-7885DEB
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same Strin…
2024-01-01Pre-auth
EPSS2.6%
pct 83
7.5
CVE-2020-1714DEB
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of Obje…
2020-01-01
EPSS2.6%
pct 83
5.9
CVE-2020-14340DEB
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of …
2020-01-01Pre-auth
EPSS2.2%
pct 80
4.3
CVE-2013-4372CVE
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss…
2013-01-01
EPSS2.2%
pct 79
7.5
CVE-2020-25644DEB
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it remo…
2020-01-01Pre-auth
EPSS2.2%
pct 79
7.5
CVE-2019-14888DEB
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listen…
2019-01-01Pre-auth
EPSS2.1%
pct 79
4.8
CVE-2017-12196DEB
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using …
2017-01-01
EPSS2.0%
pct 78
7.2
CVE-2016-8648CVE
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.…
2016-01-01
EPSS2.0%
pct 78
2.7
CVE-2015-7559DEB
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in…
2015-01-01
EPSS2.0%
pct 77
5.3
CVE-2016-8653CVE
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the…
2016-01-01Pre-auth
EPSS1.9%
pct 77
4.8
CVE-2019-10212DEB
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.securi…
2019-01-01
EPSS1.9%
pct 76
8.1
CVE-2020-1757DEB
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-…
2020-01-01
EPSS1.6%
pct 72
6.8
CVE-2014-8175CVE
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictio…
2014-01-01
EPSS1.5%
pct 70
5.3
CVE-2020-25689DEB
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controll…
2020-01-01
EPSS1.5%
pct 70
7.5
CVE-2020-10714CVE
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron…
2020-01-01Pre-auth
EPSS1.5%
pct 70
5.9
CVE-2020-10718DEB
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed pr…
2020-01-01Pre-auth
EPSS1.4%
pct 69
7.4
CVE-2021-20218CVE
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows …
2021-01-01Pre-auth
EPSS1.3%
pct 66
7.5
CVE-2020-27782DEB
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes…
2020-01-01Pre-auth
EPSS1.3%
pct 65
6.5
CVE-2020-14307DEB
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Ha…
2020-01-01
EPSS1.2%
pct 64
6.5
CVE-2020-14297DEB
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some s…
2020-01-01
EPSS1.2%
pct 64
8.8
CVE-2014-0120CVE
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote …
2014-01-01Pre-auth
EPSS1.2%
pct 62
7.4
CVE-2019-14887DEB
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols…
2019-01-01Pre-auth
EPSS1.1%
pct 60
8.8
CVE-2020-1718DEB
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw …
2020-01-01
EPSS1.0%
pct 58
5.8
CVE-2013-7397DEB
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verificat…
2013-01-01
EPSS1.0%
pct 58
8.7
CVE-2017-2589CVE
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy reques…
2017-01-01
EPSS0.9%
pct 55
5.8
CVE-2014-5075DEB
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext i…
2014-01-01
EPSS0.9%
pct 55
7.5
CVE-2022-2053DEB
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntit…
2022-01-01Pre-auth
EPSS0.9%
pct 53
3.1
CVE-2021-3642CVE
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final a…
2021-01-01
EPSS0.8%
pct 53
5.8
CVE-2013-7398DEB
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or asyn…
2013-01-01
EPSS0.8%
pct 52
2.7
CVE-2020-1717DEB
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
2020-01-01
EPSS0.8%
pct 50
4.2
CVE-2022-2764DEB
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for th…
2022-01-01
EPSS0.8%
pct 50
4.3
CVE-2019-14820DEB
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycl…
2019-01-01
EPSS0.7%
pct 48
7.5
CVE-2022-4492DEB
The undertow client is not checking the server identity presented by the server certificate in …
2022-01-01Pre-auth
EPSS0.6%
pct 43
Select a vulnerability on the left to open the preview.