Red Hat JBoss Enterprise Web Platform 5.0.0

CPE Details

Red Hat JBoss Enterprise Web Platform 5.0.0
5.0.0
2020-12-04
17h49 +00:00
2020-12-04
17h49 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:jboss_enterprise_web_platform:5.0.0:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

jboss_enterprise_web_platform

Version

5.0.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-2487 2020-03-11 14h45 +00:00 The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
5.9
Medium
CVE-2011-4610 2014-02-10 22h00 +00:00 JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."
5
CVE-2012-1167 2012-11-23 19h00 +00:00 The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
4.6