Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2019-12-04 CVE-2019-17556 Deserialization of Untrusted Data vulnerability in Apache Olingo
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized.
network
low complexity
apache CWE-502
critical
9.8
2019-12-04 CVE-2019-17554 XXE vulnerability in Apache Olingo
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities.
local
low complexity
apache CWE-611
5.5
2019-12-03 CVE-2016-1000104 Improper Input Validation vulnerability in multiple products
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
network
low complexity
apache opensuse CWE-20
8.8
2019-11-27 CVE-2011-2177 Unspecified vulnerability in Apache Openoffice 3.3.0
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
local
low complexity
apache
7.8
2019-11-26 CVE-2011-3600 XXE vulnerability in Apache Ofbiz
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem.
network
low complexity
apache CWE-611
7.5
2019-11-19 CVE-2019-12421 Insufficient Session Expiration vulnerability in Apache Nifi
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side.
network
low complexity
apache CWE-613
8.8
2019-11-19 CVE-2019-10083 Information Exposure vulnerability in Apache Nifi
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively).
network
low complexity
apache CWE-200
5.3
2019-11-19 CVE-2019-10080 XXE vulnerability in Apache Nifi
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file.
network
low complexity
apache CWE-611
6.5
2019-11-18 CVE-2019-12422 Unspecified vulnerability in Apache Shiro
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
network
low complexity
apache
7.5
2019-11-18 CVE-2019-12409 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Solr 8.1.1/8.2.0
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr.
network
low complexity
apache CWE-434
critical
9.8