Vulnerabilities > Apache > Karaf

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2016-8750 LDAP Injection vulnerability in Apache Karaf
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP.
network
low complexity
apache CWE-90
6.5
2017-11-15 CVE-2014-0219 Improper Input Validation vulnerability in Apache Karaf
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
local
low complexity
apache CWE-20
5.5