Known vulnerabilities in JBoss Web Server - page 2

Software CPE: cpe:2.3:a:red_hat:jboss_web_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 54
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting JBoss Web Server JBoss Web Server is affected by 54 known vulnerabilities: 1 critical, 9 high, 37 medium, 7 low Critical High Medium Low

Vulnerabilities (54)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-45648
CWE-444 Medium
No
No
5.7.6 10.10.2023 SB2023101084
SB2023101122
SB2023101123
and 47 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
5.7.5 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 648 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
5.7.4 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
5.7.4 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72427 - Allocation of Resources Without Limits or Throttling
CVE-2023-24998
CWE-770 Medium
Available
No
5.7.4 20.02.2023 SB2023022046
SB2023022047
SB2023030917
and 202 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
5.7.3 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
5.7.3 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
5.7.3 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
5.7.3 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71753 - Stack-based buffer overflow
CVE-2022-28331
CWE-121 High
No
No
5.7.4 02.02.2023 SB2023020208
SB2023022708
SB2023033122
and 5 more
#VU71752 - Integer overflow
CVE-2022-24963
CWE-190 High
No
No
5.7.4 02.02.2023 SB2023020209
SB2023020211
SB2023022704
and 19 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
5.7.2 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
5.7.2 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
5.7.1 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
5.7.1 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
5.6.2 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU60079 - Permissions, Privileges, and Access Controls
CVE-2022-23181
CWE-264 Low
No
No
5.7.0 27.01.2022 SB2022012708
SB2022030854
SB2022041951
and 25 more
#VU59693 - Deserialization of Untrusted Data
CVE-2020-9493
CWE-502 High
No
No
3.1.14 18.01.2022 SB2021061626
SB2022011819
SB2022012640
and 62 more
#VU56019 - Resource exhaustion
CVE-2021-30468
CWE-400 Medium
No
No
5.7.0 20.08.2021 SB2021082016
SB2021101933
SB2022042254
and 8 more
#VU51939 - Improper input validation
CVE-2021-22696
CWE-20 Medium
No
No
5.7.0 06.04.2021 SB2021040608
SB2021120219
SB2021120336
and 8 more


Showing elements 21 - 40 out of 54