Jboss Enterprise Web Platform

Vendor:

First CVE: Dec 30, 2010 · Active for 15 years

21
Total CVEs
More Total CVEs than 95% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 12% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jboss Enterprise Web Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2010
15 years ago
Most Recent CVE
Mar 11, 2020
2,330 days ago

CVE Severity & Scoring

Jboss Enterprise Web Platform21 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network2 (9.5%)
Unknown19 (90.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High2 (9.5%)
Unknown19 (90.5%)
User Interaction
None2 (9.5%)
Unknown19 (90.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (9.5%)
Unknown19 (90.5%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform
Feb 5, 20136.840NOYES
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2
Nov 23, 20127.525NONO
ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss En
Jul 23, 20137.524NONO
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy Algo
Aug 19, 20136.423NONO
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform
Jul 27, 20116.823NONO
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
Mar 11, 20205.922NONO
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise
Mar 12, 20137.521NONO
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platf
Feb 5, 20135.820NONO
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2
Jul 7, 20146.819NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Jboss Enterprise Web Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.2.0135.411.2%02
5.1.244.84.2%00
5.1.136.46.0%00
5.1.044.34.8%00
5.0.015.91.8%00