imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2011-1183
Medium 5.8

Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exist…

apache tomcat
0.06EPSS
CVE-2020-1954
Medium 5.3

Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-…

apache cxf · netapp oncommand_workflow_automation · netapp snapmanager · oracle communications_diameter_signaling_router · and 6 more
0.06EPSS
CVE-2006-1546
High 7.5

Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from application…

apache struts
0.06EPSS
CVE-2011-2088
Medium 5.0

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a differ…

apache struts · opensymphony webwork · opensymphony xwork
0.06EPSS
CVE-2022-40146
High 7.5

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.

apache batik · debian debian_linux
0.06EPSS
CVE-2020-1946
Critical 9.8

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, use…

apache spamassassin · debian debian_linux · fedoraproject fedora
0.06EPSS
CVE-2011-2087
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .ac…

apache struts
0.06EPSS
CVE-2013-6348
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.

apache struts
0.06EPSS
CVE-2015-7521
High 8.3

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations…

apache hive
0.06EPSS
CVE-2022-28615
Critical 9.1

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party …

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.06EPSS
CVE-2016-4460
Critical 9.8

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

apache pony_mail
0.06EPSS
CVE-2016-6810
Medium 6.1

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

apache activemq
0.06EPSS
CVE-2017-15706
Medium 5.3

As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execut…

apache tomcat
0.06EPSS
CVE-2016-0782
Medium 5.4

The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory…

apache activemq
0.06EPSS
CVE-2019-12423
High 7.5

Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local k…

apache cxf · oracle commerce_guided_search · oracle communications_diameter_signaling_router · oracle communications_element_manager · and 4 more
0.06EPSS
CVE-2002-2103
Medium 5.0

Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

apache http_server
0.06EPSS
CVE-2022-29404
High 7.5

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.06EPSS
CVE-2017-9801
High 7.5

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.

apache commons_email
0.06EPSS
CVE-2021-37608
Critical 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and prior versions. Upgrade to at least 17.12.08 or apply patches at https://issues.ap…

apache ofbiz
0.06EPSS
CVE-2021-45029
Critical 9.8

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

apache shenyu
0.06EPSS
CVE-2013-2210
High 7.5

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via m…

apache xml_security_for_c\+\+
0.06EPSS
CVE-2011-1582
Medium 4.3

Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this v…

apache tomcat
0.06EPSS
CVE-2018-1328
Medium 6.1

Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

apache zeppelin
0.06EPSS
CVE-2017-12174
High 7.5

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryErr…

apache artemis · redhat hornetq · redhat jboss_enterprise_application_platform
0.06EPSS
CVE-2012-4418
Medium 5.8

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

apache axis2
0.06EPSS