Apache / Tomee
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-40690 | Bypass of the secureValidation property | HIGH | 7.5 | Sep 19, 2021 |
| CVE-2021-33037 | Incorrect Transfer-Encoding handling with HTTP/1.0 | MEDIUM | 5.3 | Jul 12, 2021 |
| CVE-2021-30468 | Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter | HIGH | 7.5 | Jun 16, 2021 |
| CVE-2020-13931 | If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is mi… | CRITICAL | 9.8 | Dec 17, 2020 |
| CVE-2020-11969 | If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099… | HIGH | 9.8 | Jun 15, 2020 |
| CVE-2019-17569 | tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-17359 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted… | HIGH | 7.5 | Oct 8, 2019 |
| CVE-2019-13990 | libquartz: XXE attacks via job description | CRITICAL | 9.8 | Jul 26, 2019 |
| CVE-2018-8031 | The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web appl… | MEDIUM | 6.1 | Jul 23, 2018 |
| CVE-2016-0779 | The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized… | CRITICAL | 9.8 | Apr 11, 2017 |
Showing 1 to 10 of 10 CVEs