Known vulnerabilities in eap7-jboss-ec2-eap (Red Hat package)
Vendor:
Red Hat Inc.
Software:
eap7-jboss-ec2-eap (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:eap7-jboss-ec2-eap_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
16
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
7.1.0-5.GA_redhat_5.ep7.el6
7.1.0-5.GA_redhat_5.ep7.el7
7.0.8-1.GA_redhat_1.ep7.el6
7.0.8-1.GA_redhat_1.ep7.el7
7.0.5-1.GA_redhat_1.ep7.el6
7.0.5-1.GA_redhat_1.ep7.el7
7.0.4-5.GA_redhat_2.ep7.el6
7.0.4-5.GA_redhat_2.ep7.el7
7.0.3-3.GA_redhat_2.ep7.el6
7.0.3-3.GA_redhat_2.ep7.el7
7.0.2-2.GA_redhat_1.ep7.el6
7.0.2-2.GA_redhat_1.ep7.el7
7.0.7-1.GA_redhat_1.ep7.el6
7.0.7-1.GA_redhat_1.ep7.el7
7.1.1-3.1.GA_redhat_3.ep7.el6
7.1.1-3.1.GA_redhat_3.ep7.el7
7.0.9-2.GA_redhat_2.ep7.el6
7.0.9-2.GA_redhat_2.ep7.el7
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU14267 - Exposure of sensitive information to an unauthorized actor CVE-2017-2582 |
CWE-200 | Low | 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7 | 04.08.2018 |
SB2017031002 SB2018092411 SB2018092412 and 6 more |
||
| #VU12896 - Data Handling CVE-2016-8656 |
CWE-19 | Low | 7.0.5-1.GA_redhat_1.ep7.el6, 7.0.5-1.GA_redhat_1.ep7.el7 | 21.05.2018 |
SB2018051738 SB2017032216 |
||
| #VU12802 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2017-12196 |
CWE-300 | Low | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 17.05.2018 |
SB2018051725 SB2018031234 SB2025030774 |
||
| #VU12127 - Deserialization of Untrusted Data CVE-2017-5645 |
CWE-502 | High | 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7 | 24.04.2018 |
SB2017040201 SB2019011707 SB2017090512 and 40 more |
||
| #VU11069 - Resource exhaustion CVE-2016-9589 |
CWE-400 | Low | 7.0.5-1.GA_redhat_1.ep7.el6, 7.0.5-1.GA_redhat_1.ep7.el7 | 14.03.2018 |
SB2016031402 SB2017032216 |
||
| #VU10610 - Deserialization of Untrusted Data CVE-2018-5968 |
CWE-502 | High | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 16.02.2018 |
SB2018021604 SB2018021605 SB2018051725 and 14 more |
||
| #VU10576 - Deserialization of Untrusted Data CVE-2017-15089 |
CWE-502 | High | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 14.02.2018 |
SB2018021408 SB2018031234 SB2021040769 and 1 more |
||
| #VU10382 - Resource exhaustion CVE-2017-12174 |
CWE-400 | Low | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 06.02.2018 |
SB2018020602 SB2018020603 SB2018020607 and 3 more |
||
| #VU10257 - Deserialization of Untrusted Data CVE-2017-17485 |
CWE-502 | High | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 26.01.2018 |
SB2017121218 SB2018021605 SB2018051725 and 24 more |
||
| #VU37591 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2018-1048 |
CWE-22 | Medium | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 25.01.2018 |
SB2018012536 SB2018031234 |
||
| #VU9607 - Improper input validation CVE-2017-15095 |
CWE-20 | High | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 08.12.2017 |
SB2017121101 SB2017111609 SB2018051424 and 28 more |
||
| #VU9130 - Permissions, Privileges, and Access Controls CVE-2017-7536 |
CWE-264 | Low | 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7 | 08.11.2017 |
SB2017110807 SB2018092411 SB2018092412 and 2 more |
||
| #VU9129 - Exposure of sensitive information to an unauthorized actor CVE-2014-9970 |
CWE-200 | Low | 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7 | 08.11.2017 |
SB2017110807 SB2018021408 SB2017092625 |
||
| #VU9128 - Deserialization of Untrusted Data CVE-2017-7525 |
CWE-502 | High | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 08.11.2017 |
SB2017110807 SB2017102005 SB2017120205 and 40 more |
||
| #VU38291 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2017-7561 |
CWE-444 | Medium | 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7 | 13.09.2017 |
SB2017091336 SB2018031234 |
||
| #VU40543 - Exposure of sensitive information to an unauthorized actor CVE-2015-6644 |
CWE-200 | Low | 7.0.8-1.GA_redhat_1.ep7.el6, 7.0.8-1.GA_redhat_1.ep7.el7 | 06.01.2016 |
SB2016010604 SB2024020522 SB2017042023 and 1 more |