Jboss middleware
This hub aggregates every CVE we track for Jboss middleware, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
6
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Jboss middleware.
- CVE-2023-4066Operator: passwords defined in secrets shown in statefulset yaml5.5
- CVE-2023-4065Operator: plaintext password in operator log5.5
- CVE-2023-4853Quarkus: http security policy bypass8.1
- CVE-2018-1304The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.8...5.9
- CVE-2017-7957XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application ...7.5
- CVE-2016-3674Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XSt...7.5
Product normalization is registry-driven with AI assist and human review. How it works