Skip to main content

Vendor/product archive

redhat / jboss_operations_network CVEs

Beta · best-effort

24 CVEs tagged to redhat / jboss_operations_network4 Critical, 7 High, 8 Medium, 5 Low, 0 Unrated.

CVE-2010-0737

Published Oct 30, 2019

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tas…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3834

Published Oct 3, 2019

It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6330

Published Sep 27, 2016

The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5422

Published Sep 7, 2016

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticate…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3737

Published Aug 2, 2016

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3267

Published Aug 11, 2015

Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0297

Published Apr 24, 2015

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvoker…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0032

Published Apr 1, 2014

Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdir…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-4573

Published Apr 1, 2014

Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration up…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1100

Published Feb 14, 2014

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0062

Published Feb 14, 2014

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security to…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0052

Published Feb 14, 2014

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agent…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4452

Published Dec 24, 2013

Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication cred…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4373

Published Oct 24, 2013

The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4293

Published Oct 24, 2013

The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2165

Published Jul 23, 2013

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss E…

CVSS 7.5 · High
Showing 1-24 of 24 CVEsPage 1 of 1