Jboss Data Grid

Vendor:

First CVE: Apr 13, 2017 · Active for 9 years

25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Jboss Data Grid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2017
9 years ago
Most Recent CVE
Dec 18, 2023
952 days ago

CVE Severity & Scoring

Jboss Data Grid25 CVEs
All CVEs352,727 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None24 (96.0%)
Unknown0 (0.0%)
Required1 (4.0%)
Privileges Required
Low10 (40.0%)
High1 (4.0%)
None14 (56.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName
Dec 14, 20217.570NONO
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-con
Mar 2, 20209.833NONO
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs t
Jun 12, 20199.833NONO
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials fr
Oct 2, 20199.831NONO
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can o
Aug 31, 20228.830NONO
A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect
Jan 2, 20209.830NONO
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
Apr 13, 20177.530NONO
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla
Nov 25, 20198.829NONO
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf
Mar 16, 20209.128NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Jboss Data Grid

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.218.81.3%00
7.127.06.4%00
7.0.0137.715.9%11
6.0.015.92.2%00