|
CVE-2015-0886
|
Medium
|
2015-02-28
|
No exploit published
|
No public exploit
|
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
|
|
CVE-2014-8114
|
Medium
|
2015-02-20
|
Protected by RASP
|
No public exploit
|
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.
|
|
CVE-2014-0005
|
Low
|
2015-02-20
|
No fix identified
|
No public exploit
|
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
|
|
CVE-2014-3578
|
Medium
|
2015-02-19
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
|
|
CVE-2015-1427
|
Critical
|
2015-02-17
|
Mitigation candidate
|
Exploited in the wild
|
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
|
|
CVE-2014-8122
|
Medium
|
2015-02-13
|
No exploit published
|
No public exploit
|
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
|
|
CVE-2014-7853
|
Medium
|
2015-02-13
|
No fix identified
|
No public exploit
|
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
|
|
CVE-2014-7849
|
Medium
|
2015-02-13
|
No exploit published
|
No public exploit
|
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
|
|
CVE-2014-7827
|
Low
|
2015-02-13
|
No fix identified
|
No public exploit
|
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
|
|
CVE-2015-0227
|
Medium
|
2015-02-12
|
Mitigation candidate
|
No public exploit
|
Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."
|
|
CVE-2014-8110
|
Medium
|
2015-02-12
|
No exploit published
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|