Red hat jboss enterprise application platform 6
This hub aggregates every CVE we track for Red hat jboss enterprise application platform 6, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
12
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM6
Monthly trend
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Red hat jboss enterprise application platform 6.
- CVE-2023-4639Undertow: cookie smuggling/spoofing7.4
- CVE-2023-1932Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss6.1
- CVE-2024-1102Jberet: jberet-core logging database credentials6.5
- CVE-2023-6717Keycloak: xss via assertion consumer service url in saml post-binding flow6.0
- CVE-2024-1249Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos7.4
- CVE-2024-1132Keycloak: path transversal in redirection validation8.1
- CVE-2023-6291Keycloak: redirect_uri validation bypass7.1
- CVE-2023-3629Infinispan: non-admins should not be able to get cache config via rest api4.3
- CVE-2023-3628Infispan: rest bulk ops don't check permissions6.5
- CVE-2022-4245Codehaus-plexus: xml external entity (xxe) injection4.3
- CVE-2022-4244Codehaus-plexus: directory traversal7.5
- CVE-2022-1415Drools: unsafe data deserialization in streamutils8.1
Product normalization is registry-driven with AI assist and human review. How it works