Known vulnerabilities in JBoss Data Grid - page 7

Software CPE: cpe:2.3:a:red_hat:jboss_data_grid:*:*:*:*:*:*:*:*
Total vulnerabilities: 141
Public exploits: 14
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting JBoss Data Grid JBoss Data Grid is affected by 141 known vulnerabilities: 2 critical, 39 high, 75 medium, 25 low Critical High Medium Low

Vulnerabilities (141)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU25834 - Deserialization of Untrusted Data
CVE-2019-14893
CWE-502 High
No
No
7.3.5 09.03.2020 SB2020030911
SB2020031901
SB2022060909
and 15 more
#VU25833 - Deserialization of Untrusted Data
CVE-2019-14892
CWE-502 High
No
No
7.3.5 09.03.2020 SB2020030911
SB2020031901
SB2022060909
and 16 more
#VU23379 - Session Fixation
CVE-2019-10158
CWE-384 Low
No
No
7.3.2 04.12.2019 SB2019061818
SB2019120401
#VU22830 - Deserialization of Untrusted Data
CVE-2016-0750
CWE-502 Medium
No
No
7.1.1 19.11.2019 SB2018091110
SB2021040769
SB2017111658
and 1 more
#VU21136 - Exposure of sensitive information to an unauthorized actor
CVE-2019-16335
CWE-200 Medium
No
No
7.3.5 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 21 more
#VU19943 - Deserialization of Untrusted Data
CVE-2018-12023
CWE-502 Medium
No
No
7.3.2 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 20 more
#VU19942 - Deserialization of Untrusted Data
CVE-2018-12022
CWE-502 Medium
No
No
7.3.2 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 18 more
#VU19938 - Deserialization of Untrusted Data
CVE-2018-11307
CWE-502 High
No
No
7.3.2 06.08.2019 SB2019052407
SB2019091718
SB2019092703
and 17 more
#VU17781 - Improper input validation
CVE-2018-19362
CWE-20 High
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 38 more
#VU17780 - Improper input validation
CVE-2018-19360
CWE-20 High
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17779 - Improper input validation
CVE-2018-19361
CWE-20 High
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 23 more
#VU17778 - Improper input validation
CVE-2018-14719
CWE-20 High
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019091718
and 22 more
#VU17777 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2018-14720
CWE-611 Low
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 21 more
#VU17776 - Server-Side Request Forgery (SSRF)
CVE-2018-14721
CWE-918 Low
No
No
7.3.2 19.02.2019 SB2018121501
SB2019052407
SB2019092703
and 23 more
#VU17053 - Permissions, Privileges, and Access Controls
CVE-2018-14718
CWE-264 High
No
No
7.3.2 17.01.2019 SB2019011703
SB2019052407
SB2019091718
and 29 more
#VU12127 - Deserialization of Untrusted Data
CVE-2017-5645
CWE-502 High
No
No
7.1.1 24.04.2018 SB2017040201
SB2019011707
SB2017090512
and 40 more
#VU11301 - Improper Access Control
CVE-2018-8088
CWE-284 Low
No
No
- 28.03.2018 SB2018022112
SB2018032813
SB2018032817
and 27 more
#VU10576 - Deserialization of Untrusted Data
CVE-2017-15089
CWE-502 High
No
No
- 14.02.2018 SB2018021408
SB2018031234
SB2021040769
and 1 more
#VU9129 - Exposure of sensitive information to an unauthorized actor
CVE-2014-9970
CWE-200 Low
No
No
- 08.11.2017 SB2017110807
SB2018021408
SB2017092625
#VU9128 - Deserialization of Untrusted Data
CVE-2017-7525
CWE-502 High
Available
No
- 08.11.2017 SB2017110807
SB2017102005
SB2017120205
and 41 more


Showing elements 121 - 140 out of 141