Jboss Middleware
Vendor:
First CVE: May 17, 2016 · Active for 10 years
6
Total CVEs
More Total CVEs than 83% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jboss Middleware over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2016
10 years ago
Most Recent CVE
Sep 27, 2023
1,035 days ago
CVE Severity & Scoring
Jboss Middleware6 CVEs
50%
50%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High2 (33.3%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1304MEDIUM The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 a | Feb 28, 2018 | 5.9 | 28 | NO | NO |
CVE-2016-3674HIGH Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriv | May 17, 2016 | 7.5 | 28 | NO | NO |
CVE-2017-7957HIGH XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a re | Apr 29, 2017 | 7.5 | 27 | NO | NO |
CVE-2023-4853HIGH A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of p | Sep 20, 2023 | 8.1 | 25 | NO | NO |
CVE-2023-4066MEDIUM A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown | Sep 27, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-4065MEDIUM A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an au | Sep 27, 2023 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Jboss Middleware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1 | 6 | 6.7 | 5.3% | 0 | 0 |