Vulnerabilities
Vulnerable Software
Redhat:  Security Vulnerabilities
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
CVSS Score
6.5
EPSS Score
0.002
Published
2017-09-20
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
CVSS Score
5.9
EPSS Score
0.003
Published
2017-09-19
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-19
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
CVSS Score
9.8
EPSS Score
0.028
Published
2017-09-19
CVE-2017-12615
Known exploited
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVSS Score
8.1
EPSS Score
0.942
Published
2017-09-19
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.
CVSS Score
4.7
EPSS Score
0.0
Published
2017-09-14
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
CVSS Score
7.5
EPSS Score
0.003
Published
2017-09-14
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
CVSS Score
9.8
EPSS Score
0.021
Published
2017-09-14
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
CVSS Score
9.8
EPSS Score
0.021
Published
2017-09-14
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
CVSS Score
9.8
EPSS Score
0.021
Published
2017-09-14


Contact Us

Shodan ® - All rights reserved