Known vulnerabilities in JBoss Data Grid - page 3

Software CPE: cpe:2.3:a:red_hat:jboss_data_grid:*:*:*:*:*:*:*:*
Total vulnerabilities: 103
Public exploits: 12
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting JBoss Data Grid JBoss Data Grid is affected by 103 known vulnerabilities: 2 critical, 30 high, 48 medium, 23 low Critical High Medium Low

Vulnerabilities (103)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73956 - Server-Side Request Forgery (SSRF)
CVE-2021-39152
CWE-918 High
Available
No
8.3.0 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73949 - Deserialization of Untrusted Data
CVE-2021-39146
CWE-502 High
No
No
8.3.0 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73948 - Deserialization of Untrusted Data
CVE-2021-39145
CWE-502 High
No
No
8.3.0 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 14 more
#VU67668 - Stack-based buffer overflow
CVE-2022-38750
CWE-121 Medium
No
No
8.4.0 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 50 more
#VU67666 - Stack-based buffer overflow
CVE-2022-38749
CWE-121 Medium
No
No
8.4.0 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 51 more
#VU67665 - Resource exhaustion
CVE-2022-25857
CWE-400 Medium
No
No
8.4.0 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 83 more
#VU67664 - Stack-based buffer overflow
CVE-2022-38752
CWE-121 Medium
No
No
8.4.0 27.09.2022 SB2022092715
SB2022092728
SB2022100555
and 66 more
#VU67663 - Out-of-bounds write
CVE-2022-38751
CWE-787 Medium
No
No
8.4.0 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 50 more
#VU63159 - Allocation of Resources Without Limits or Throttling
CVE-2022-0084
CWE-770 Low
No
No
8.3.1 13.05.2022 SB2022051310
SB2022051311
SB2022060838
and 12 more
#VU62849 - Creation of Temporary File With Insecure Permissions
CVE-2022-24823
CWE-378 Low
No
No
8.4.0 09.05.2022 SB2022050902
SB2022063002
SB2022072013
and 55 more
#VU62511 - Improper input validation
CVE-2021-39140
CWE-20 Medium
No
No
8.3.0 22.04.2022 SB2022042257
SB2023012518
SB2023032239
and 15 more
#VU61810 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-43797
CWE-444 Medium
No
No
8.3.0 02.04.2022 SB2021120923
SB2022040202
SB2022042223
and 49 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
8.3.1 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61471 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0235
CWE-200 Low
No
No
8.4.0 20.03.2022 SB2022032001
SB2022032002
SB2022032009
and 35 more
#VU60729 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-23647
CWE-79 Low
No
No
8.4.0 21.02.2022 SB2022022105
SB2022100650
SB2022111738
and 1 more
#VU59813 - Improper input validation
CVE-2021-39139
CWE-20 High
No
No
8.3.0 19.01.2022 SB2022011911
SB2022011912
SB2022012325
and 21 more
#VU59701 - Improper input validation
CVE-2021-39154
CWE-20 High
No
No
8.3.0 18.01.2022 SB2022011835
SB2023032239
SB2023050815
and 12 more
#VU59661 - Observable discrepancy
CVE-2021-3642
CWE-203 Low
No
No
8.3.0 17.01.2022 SB2021080530
SB2022080830
SB2021121543
and 1 more
#VU56790 - Information Exposure Through Timing Discrepancy
CVE-2021-38153
CWE-208 Low
No
No
8.3.1 21.09.2021 SB2021092116
SB2022010906
SB2022012104
and 21 more
#VU54675 - Deserialization of Untrusted Data
CVE-2021-29505
CWE-502 Medium
Available
No
8.3.0 12.07.2021 SB2021071217
SB2021071218
SB2021071389
and 19 more


Showing elements 41 - 60 out of 103