target entity

Red Hat

7 source-linked records in the current knowledge graph.

high

CVE-2018-14667: Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-14667EPSS 74.2%JBoss RichFaces FrameworkRed Hat
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2010-1428: Red Hat JBoss Information Disclosure Vulnerability

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. Required action: Apply updates per vendor instructions.

CVE-2010-1428EPSS 62.3%JBossRed Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0738: Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. Required action: Apply updates per vendor instructions.

CVE-2010-0738EPSS 79.4%JBossRed Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2010-1871: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured. Required action: Apply updates per vendor instructions.

CVE-2010-1871EPSS 83.4%JBoss Seam 2Red Hat
CISA KEV ↗ · unattributed attribution