-Infinity
0

redhat JBoss Enterprise Application PlatformUndertow: undertow: request smuggling via malformed http request headers

Risk 66
Severity
9.1
First published (updated )

JBoss UndertowUndertow splits header names from values on either space or colon, whichever comes first. This allow…

Risk 33
Severity
7
First published (updated )

JBoss UndertowWhen Undertow receives a request in which the first header line begins with one or more spaces, it s…

Risk 33
Severity
7
First published (updated )

JBoss UndertowProblems with Undertow cookie parsing may lead to smuggling or spoofing of cookies in certain condit…

Risk 19
Severity
4
First published (updated )

JBoss Keycloak NodeJS AdapterBug URL: https://issues.jboss.org/browse/KEYCLOAK-10389 In order to be aligned with the other adapt…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JBoss UndertowUndertow has a file handler leak vulnerability caused by JarURLConnection.getLastModified(). A remot…

Risk 19
Severity
4
First published (updated )

redhat JBoss Enterprise Application PlatformA vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3…

Risk 43
Severity
7.5
First published (updated )

JBoss WildflyA flaw was found in Wildfly 9.x. A patch traversal vulnerability through the org.wildfly.extension.u…

Risk 19
Severity
4
First published (updated )

JBoss UndertowUndertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache …

Risk 19
Severity
4
First published (updated )

JBoss BPM SuiteXSS

Risk 18
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JBoss DashbuilderSQL Injection

Risk 33
Severity
7
First published (updated )

JBoss Enterprise Application PlatformThe HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by…

Risk 45
Severity
7.5
First published (updated )

JBOSS JBossIt was discovered that when dealing with undefined security domains, the org.jboss.security.plugins.…

Risk 5
Severity
1
First published (updated )

JBoss TeiidTeiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows …

Risk 22
Severity
4.3
First published (updated )

JBoss KeycloakIt was discovered that by requesting a large enough image size for a generated QR code, a remote att…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JBoss Enterprise Portal PlatformImportant: JBoss Enterprise Portal Platform 5.2.2 security update

Risk 66
First published (updated )

JBoss PicketBoxIt was identified that security auditing provided by JBossSX/PicketBox logged sensitive information …

Risk 5
Severity
1
First published (updated )

JBoss SOA RTgovA code execution vulnerability has been discovered in JBoss SOA RTgov. The flaw allows remote authen…

Risk 32
Severity
7
First published (updated )

JBoss PicketBoxIssueDescription: It was identified that PicketBox/JBossSX allowed any deployed application to alte…

Risk 18
Severity
4
First published (updated )

JBoss Seam RemotingIt was found that the InterfaceGenerator handler in JBoss Seam Remoting will expose details of all c…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JBoss JBoss Web ServicesImportant: JBoss Enterprise Application Platform 5.2.0 update

Risk 66
First published (updated )

maven/org.jboss.ironjacamar:ironjacamar-jdbcThe IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-user…

Risk 22
Severity
4.3
First published (updated )

JBoss JBoss Application ServerWhen using multi-user authentication provided by the "allow-multiple-users" option for the datasourc…

Risk 19
Severity
4
First published (updated )

JBoss Enterprise Application PlatformWhen a JGroups channel is started, the JGroups diagnostics service will be enabled by default with n…

Risk 5
Severity
1
First published (updated )

JBoss JBoss WebImportant: jbossweb security update

Risk 42
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

JBoss RESTEasyRESTEasy permits XXE (XML eXternal Entity) attacks. If a RESTEasy endpoint is deployed, a user can s…

Risk 19
Severity
4
First published (updated )

JBoss EAPCSRF

Risk 18
Severity
4
First published (updated )

JBoss Application ServerWe have received information from a third party regarding vulnerabilities in JBoss Application Serve…

Risk 18
Severity
4
First published (updated )

redhat/jbossasThe status servlet exposes details about the deployed servlets and makes it easier to identity the a…

Risk 26
Severity
5
First published (updated )

JBoss seamInput Validation

Risk 52
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203