Red Hat JBoss Web Framework Kit 2.5.0

CPE Details

Red Hat JBoss Web Framework Kit 2.5.0
2.5.0
2014-03-31
15h29 +00:00
2014-04-02
12h06 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:jboss_web_framework_kit:2.5.0:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

jboss_web_framework_kit

Version

2.5.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-0248 2014-07-07 12h00 +00:00 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
6.8
CVE-2014-0149 2014-05-05 15h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.
4.3
CVE-2014-0086 2014-03-28 16h00 +00:00 The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.
4.3