|
CVE-2016-2174
|
High
|
2016-06-13
|
Protected by RASP
|
No public exploit
|
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
|
|
CVE-2016-3720
|
Critical
|
2016-06-10
|
Protected by RASP
|
No public exploit
|
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
|
|
CVE-2015-7611
|
High
|
2016-06-07
|
Protected by RASP
|
Working exploit published
|
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.
|
|
CVE-2016-2175
|
High
|
2016-06-01
|
Protected by RASP
|
No public exploit
|
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
|