Red Hat / Decision Manager
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-4853 | Quarkus: http security policy bypass | HIGH | 8.1 | Sep 20, 2023 |
| CVE-2023-1108 | Undertow: infinite loop in sslconduit during close | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2022-1415 | Drools: unsafe data deserialization in streamutils | HIGH | 8.8 | Sep 11, 2023 |
| CVE-2019-14841 | RHDM: admin console auth bypass | HIGH | 8.8 | Oct 17, 2022 |
| CVE-2019-14840 | Business-central: Sensitive HTML Form Fields like Password has auto-complete Enabled | HIGH | 7.5 | Oct 17, 2022 |
| CVE-2020-1748 | Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain | HIGH | 7.5 | Sep 16, 2020 |
| CVE-2019-14900 | hibernate: SQL injection issue in Hibernate ORM | MEDIUM | 6.5 | Jul 6, 2020 |
| CVE-2020-1714 | keycloak: Lack of checks in ObjectInputStream leading to Remote Code Execution | HIGH | 8.8 | May 13, 2020 |
| CVE-2020-1720 | postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks | MEDIUM | 6.5 | Mar 17, 2020 |
| CVE-2019-14886 | Business-central: Encrypted password shown under Object id 7 of errai_security_context | MEDIUM | 6.5 | Mar 5, 2020 |
| CVE-2019-14892 | jackson-databind: Serialization gadgets in classes of the commons-configuration package | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2019-14863 | angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes | MEDIUM | 6.1 | Jan 2, 2020 |
| CVE-2019-14862 | knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute. | MEDIUM | 6.1 | Jan 2, 2020 |
| CVE-2018-12022 | jackson-databind: improper polymorphic deserialization of types from Jodd-db library | HIGH | 7.5 | Mar 17, 2019 |
| CVE-2018-12023 | jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver | HIGH | 7.5 | Mar 17, 2019 |
| CVE-2018-19362 | jackson-databind: improper polymorphic deserialization in jboss-common-core class | CRITICAL | 9.8 | Jan 2, 2019 |
| CVE-2018-19361 | jackson-databind: improper polymorphic deserialization in openjpa class | CRITICAL | 9.8 | Jan 2, 2019 |
| CVE-2018-19360 | jackson-databind: improper polymorphic deserialization in axis2-transport-jms class | CRITICAL | 9.8 | Jan 2, 2019 |
| CVE-2017-7545 | jbpmmigration: XXE vulnerability in XmlUtils | MEDIUM | 6.5 | Jul 26, 2018 |
Showing 1 to 20 of 20 CVEs