Skip to main content

Vendor/product archive

apache / jetspeed CVEs

Beta · best-effort

6 CVEs tagged to apache / jetspeed1 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-32533

Published Jul 6, 2022

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2171

Published Apr 11, 2016

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) dele…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0712

Published Apr 11, 2016

Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0711

Published Apr 11, 2016

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when addi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0710

Published Apr 11, 2016

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2)…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0709

Published Apr 11, 2016

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1