Skip to main content

Vendor/product archive

redhat / jboss_application_server CVEs

Beta · best-effort

5 CVEs tagged to redhat / jboss_application_server0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2012-1094

Published Mar 10, 2020

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be ex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3609

Published Nov 26, 2019

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Contro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3606

Published Nov 26, 2019

A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted w…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3734

Published Oct 24, 2017

The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1