Red Hat / Jboss A-MQ
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-4066 | Operator: passwords defined in secrets shown in statefulset yaml | MEDIUM | 5.5 | Sep 27, 2023 |
| CVE-2023-4065 | Operator: plaintext password in operator log | MEDIUM | 5.5 | Sep 26, 2023 |
| CVE-2023-1664 | keycloak: Untrusted Certificate Validation | MEDIUM | 6.5 | May 26, 2023 |
| CVE-2022-1278 | WildFly: possible information disclosure | HIGH | 7.5 | Sep 13, 2022 |
| CVE-2020-14379 | broker: XXE injection in configuration files | MEDIUM | 5.6 | Aug 16, 2022 |
| CVE-2021-4104 | Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2 | HIGH | 7.5 | Dec 14, 2021 |
| CVE-2021-3425 | Broker: discloses JDBC username and password in the application log file | MEDIUM | 4.4 | Jun 1, 2021 |
| CVE-2021-3536 | wildfly: XSS via admin console when creating roles in domain mode | MEDIUM | 4.8 | May 20, 2021 |
| CVE-2015-7559 | ActiveMQ: DoS in client via shutdown command | LOW | 2.7 | Aug 1, 2019 |
| CVE-2016-8653 | Fuse-6: JMX endpoint deserializes untrusted credentials. | MEDIUM | 5.3 | Aug 1, 2018 |
| CVE-2016-8648 | Karaf JMX Console RCE during deserialization | HIGH | 7.2 | Aug 1, 2018 |
| CVE-2015-7501 | apache-commons-collections: InvokerTransformer code execution during deserialisation | CRITICAL | 9.8 | Nov 9, 2017 |
| CVE-2015-5183 | Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ | HIGH | 7.5 | Sep 25, 2017 |
| CVE-2015-5181 | The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. | MEDIUM | 5.4 | Sep 25, 2017 |
| CVE-2014-0085 | JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local… | LOW | 2.1 | Apr 17, 2014 |
| CVE-2013-4372 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 a… | MEDIUM | 4.3 | Sep 30, 2013 |
Showing 1 to 17 of 17 CVEs