Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2019-05-28 CVE-2018-17198 Server-Side Request Forgery (SSRF) vulnerability in Apache Roller
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability.
network
low complexity
apache CWE-918
critical
9.8
2019-05-23 CVE-2019-0201 Missing Authorization vulnerability in multiple products
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta.
network
high complexity
apache debian redhat oracle netapp CWE-862
5.9
2019-05-20 CVE-2019-10078 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
network
low complexity
apache CWE-79
6.1
2019-05-20 CVE-2019-10077 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
network
low complexity
apache CWE-79
6.1
2019-05-20 CVE-2019-10076 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
network
low complexity
apache CWE-79
6.1
2019-05-09 CVE-2019-0226 Path Traversal vulnerability in Apache Karaf
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file.
network
low complexity
apache CWE-22
4.9
2019-05-06 CVE-2018-17202 Infinite Loop vulnerability in Apache Commons Imaging 0.97
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack.
network
low complexity
apache CWE-835
7.5
2019-05-06 CVE-2018-17201 Unspecified vulnerability in Apache Commons Imaging 0.97
Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack.
network
low complexity
apache
7.5
2019-05-01 CVE-2019-0227 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006.
high complexity
apache oracle CWE-918
7.5
2019-05-01 CVE-2018-8035 Cross-site Scripting vulnerability in Apache Uimaducc
This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.
network
low complexity
apache CWE-79
6.1