Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2016-6815 Credentials Management vulnerability in Apache Ranger
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
network
low complexity
apache CWE-255
6.5
2017-10-12 CVE-2016-8736 Deserialization of Untrusted Data vulnerability in Apache Openmeetings
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
network
low complexity
apache CWE-502
critical
9.8
2017-10-10 CVE-2017-12623 XXE vulnerability in Apache Nifi
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack.
network
low complexity
apache CWE-611
6.5
2017-10-10 CVE-2017-5637 Missing Authentication for Critical Function vulnerability in multiple products
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.
network
low complexity
apache debian CWE-306
7.5
2017-10-10 CVE-2014-0030 XXE vulnerability in Apache Roller
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
network
low complexity
apache CWE-611
critical
9.8
2017-10-04 CVE-2017-9792 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Impala 2.8.0/2.9.0
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables.
network
low complexity
apache CWE-732
6.5
2017-10-04 CVE-2017-12617 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
network
high complexity
apache canonical oracle debian netapp redhat CWE-434
8.1
2017-10-03 CVE-2017-9797 Information Exposure vulnerability in Apache Geode
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages.
network
high complexity
apache CWE-200
6.5
2017-10-03 CVE-2017-12620 XXE vulnerability in Apache Opennlp
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources.
network
low complexity
apache CWE-611
critical
9.8
2017-10-03 CVE-2016-6806 Cross-Site Request Forgery (CSRF) vulnerability in Apache Wicket
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests.
network
low complexity
apache CWE-352
8.8