|
CVE-2015-2918
|
Medium
|
2015-12-31
|
No exploit published
|
No public exploit
|
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
|
|
CVE-2015-2913
|
Medium
|
2015-12-31
|
No exploit published
|
No public exploit
|
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
|
|
CVE-2015-2912
|
High
|
2015-12-31
|
No exploit published
|
No public exploit
|
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
|
|
CVE-2015-1836
|
High
|
2015-12-21
|
No exploit published
|
No public exploit
|
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.
|
|
CVE-2015-1772
|
High
|
2015-12-21
|
No exploit published
|
No public exploit
|
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
|
|
CVE-2015-5304
|
Low
|
2015-12-16
|
No exploit published
|
No public exploit
|
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.
|
|
CVE-2015-5326
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
|
|
CVE-2015-5325
|
High
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
|
|
CVE-2015-5324
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
|
|
CVE-2015-5323
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
|
|
CVE-2015-5321
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
|
|
CVE-2015-5320
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
|
|
CVE-2015-5318
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack.
|
|
CVE-2014-3665
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
|
|
CVE-2015-5253
|
Medium
|
2015-11-18
|
No exploit published
|
No public exploit
|
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
|
|
CVE-2015-5210
|
Medium
|
2015-11-02
|
No exploit published
|
No public exploit
|
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
|
|
CVE-2015-1775
|
Medium
|
2015-11-02
|
No exploit published
|
No public exploit
|
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
|
|
CVE-2015-5262
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
|
|
CVE-2015-5220
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
|
|
CVE-2015-5188
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.
|
|
CVE-2015-5178
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
|
|
CVE-2015-1814
|
High
|
2015-10-16
|
No exploit published
|
No public exploit
|
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
|
|
CVE-2015-1813
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.
|
|
CVE-2015-1812
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.
|
|
CVE-2015-1810
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.
|
|
CVE-2015-1808
|
Low
|
2015-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
|
|
CVE-2015-1806
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
|
|
CVE-2015-5235
|
Medium
|
2015-10-09
|
No exploit published
|
No public exploit
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
|
|
CVE-2015-5234
|
Medium
|
2015-10-09
|
No exploit published
|
No public exploit
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
|
|
CVE-2015-3158
|
Medium
|
2015-08-26
|
No exploit published
|
No public exploit
|
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
|
|
CVE-2015-6524
|
Medium
|
2015-08-24
|
No exploit published
|
No public exploit
|
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
|
|
CVE-2014-3612
|
High
|
2015-08-24
|
No exploit published
|
No public exploit
|
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
|
|
CVE-2015-4749
|
Medium
|
2015-07-16
|
No exploit published
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect availability via vectors related to JNDI.
|
|
CVE-2015-3244
|
Medium
|
2015-07-16
|
No exploit published
|
No public exploit
|
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
|
|
CVE-2015-1831
|
High
|
2015-07-16
|
No exploit published
|
No public exploit
|
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
|
|
CVE-2013-7398
|
Medium
|
2015-06-24
|
No exploit published
|
No public exploit
|
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
|
|
CVE-2013-7397
|
Medium
|
2015-06-24
|
No exploit published
|
No public exploit
|
Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to spoof HTTPS servers by presenting an arbitrary certificate during use of a typical AHC configuration, as demonstrated by a configuration that does not send client certificates.
|
|
CVE-2014-7810
|
Medium
|
2015-06-07
|
No exploit published
|
No public exploit
|
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
|
|
CVE-2014-0230
|
High
|
2015-06-07
|
No exploit published
|
No public exploit
|
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
|
|
CVE-2015-2944
|
Medium
|
2015-06-02
|
No exploit published
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.
|
|
CVE-2014-3586
|
Low
|
2015-04-21
|
No exploit published
|
No public exploit
|
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.
|
|
CVE-2015-0488
|
Medium
|
2015-04-16
|
No exploit published
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
|
|
CVE-2015-0478
|
Medium
|
2015-04-16
|
No exploit published
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
|
|
CVE-2015-2351
|
Medium
|
2015-03-19
|
No exploit published
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to system/workplace/locales/en/help/index.html, (3) path parameter to system/workplace/views/admin/admin-main.jsp, (4) mode parameter to system/workplace/views/explorer/explorer_files.jsp, or (5) query parameter in a search action to system/modules/org.opencms.workplace.help/elements/search.jsp.
|
|
CVE-2015-0886
|
Medium
|
2015-02-28
|
No exploit published
|
No public exploit
|
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
|
|
CVE-2014-8122
|
Medium
|
2015-02-13
|
No exploit published
|
No public exploit
|
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
|
|
CVE-2014-7849
|
Medium
|
2015-02-13
|
No exploit published
|
No public exploit
|
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
|
|
CVE-2015-0227
|
Medium
|
2015-02-12
|
No exploit published
|
No public exploit
|
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
|
|
CVE-2014-8110
|
Medium
|
2015-02-12
|
No exploit published
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
|
CVE-2014-8152
|
Medium
|
2015-01-21
|
No exploit published
|
No public exploit
|
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.
|
|
CVE-2014-9527
|
Medium
|
2015-01-06
|
No exploit published
|
No public exploit
|
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
|
|
CVE-2014-3628
|
Medium
|
2015-01-06
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache object.
|