Skip to main content

Vendor/product archive

redhat / jboss_data_grid CVEs

Beta · best-effort

24 CVEs tagged to redhat / jboss_data_grid5 Critical, 10 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2020-25689

Published Nov 2, 2020

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly c…

CVSS 5.3 · Medium

CVE-2020-25644

Published Oct 6, 2020

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of s…

CVSS 7.5 · High

CVE-2019-14900

Published Jul 6, 2020

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals…

CVSS 6.5 · Medium

CVE-2019-14892

Published Mar 2, 2020

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-co…

CVSS 9.8 · Critical

CVE-2019-10174

Published Nov 25, 2019

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cl…

CVSS 8.8 · High

CVE-2019-10212

Published Oct 2, 2019

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials f…

CVSS 9.8 · Critical
Showing 1-24 of 24 CVEsPage 1 of 1