Apache / Jetspeed
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-32533 | Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues | CRITICAL | 9.8 | Jul 6, 2022 |
| CVE-2016-2171 | The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (… | HIGH | 7.5 | Apr 11, 2016 |
| CVE-2016-0712 | Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to po… | MEDIUM | 6.1 | Apr 11, 2016 |
| CVE-2016-0711 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title… | MEDIUM | 6.1 | Apr 11, 2016 |
| CVE-2016-0710 | Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via… | HIGH | 8.8 | Apr 11, 2016 |
| CVE-2016-0709 | Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administ… | HIGH | 7.2 | Apr 11, 2016 |
Showing 1 to 6 of 6 CVEs