Skip to main content

Vendor/product archive

apache / tomee CVEs

Beta · best-effort

9 CVEs tagged to apache / tomee3 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2020-13931

Published Dec 18, 2020

If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX p…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11969

Published Jun 15, 2020

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not inc…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8031

Published Jul 23, 2018

The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0779

Published Apr 11, 2017

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1