Jboss Data Grid
Vendor:
First CVE: Apr 13, 2017 · Active for 9 years
25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Jboss Data Grid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2017
9 years ago
Most Recent CVE
Dec 18, 2023
952 days ago
CVE Severity & Scoring
Jboss Data Grid25 CVEs
36%
40%
20%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None24 (96.0%)
Unknown0 (0.0%)
Required1 (4.0%)
Privileges Required
Low10 (40.0%)
High1 (4.0%)
None14 (56.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2019-14892CRITICAL A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-con | Mar 2, 2020 | 9.8 | 33 | NO | NO |
CVE-2019-3888CRITICAL A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs t | Jun 12, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-10212CRITICAL A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials fr | Oct 2, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-1271HIGH An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can o | Aug 31, 2022 | 8.8 | 30 | NO | NO |
CVE-2019-10158CRITICAL A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect | Jan 2, 2020 | 9.8 | 30 | NO | NO |
CVE-2016-4970HIGH handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | Apr 13, 2017 | 7.5 | 30 | NO | NO |
CVE-2019-10174HIGH A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla | Nov 25, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-14887CRITICAL A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf | Mar 16, 2020 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
1 CVE
4.0% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Jboss Data Grid
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2 | 1 | 8.8 | 1.3% | 0 | 0 |
| 7.1 | 2 | 7.0 | 6.4% | 0 | 0 |
| 7.0.0 | 13 | 7.7 | 15.9% | 1 | 1 |
| 6.0.0 | 1 | 5.9 | 2.2% | 0 | 0 |