Skip to main content

Vendor/product archive

redhat / wildfly CVEs

Beta · best-effort

18 CVEs tagged to redhat / wildfly2 Critical, 3 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2021-3644

Published Aug 26, 2022

A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to t…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-3503

Published Apr 18, 2022

A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1719

Published Jun 7, 2021

A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3536

Published May 20, 2021

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, lead…

CVSS 4.8 · Medium

CVE-2020-27822

Published Dec 8, 2020

A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interc…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25640

Published Nov 24, 2020

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25689

Published Nov 2, 2020

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly c…

CVSS 5.3 · Medium

CVE-2020-10718

Published Sep 16, 2020

A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This sett…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10740

Published Jun 22, 2020

A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of val…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14627

Published Sep 4, 2018

The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10683

Published May 9, 2018

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1