Vulnerabilities
Vulnerable Software
Redhat:  >> Jboss Data Grid  Security Vulnerabilities
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
CVSS Score
5.3
EPSS Score
0.011
Published
2019-07-25
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
CVSS Score
5.3
EPSS Score
0.006
Published
2019-06-12
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
CVSS Score
6.5
EPSS Score
0.006
Published
2018-07-16
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept certain types of objects, achieving code execution and possible further attacks. Versions 9.0.3.Final, 9.1.7.Final, 8.2.10.Final, 9.2.2.Final, 9.3.0.Alpha1 are believed to be affected.
CVSS Score
8.8
EPSS Score
0.007
Published
2018-05-15
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
CVSS Score
7.5
EPSS Score
0.082
Published
2017-04-13


Contact Us

Shodan ® - All rights reserved