Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-11969 Missing Authentication for Critical Function vulnerability in Apache Tomee
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication.
network
low complexity
apache CWE-306
critical
9.8
2020-06-05 CVE-2020-11975 Unspecified vulnerability in Apache Unomi 1.3.0/1.4.0/1.5.0
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
network
low complexity
apache
critical
9.8
2020-06-03 CVE-2020-1963 Missing Authorization vulnerability in Apache Ignite
Apache Ignite uses H2 database to build SQL distributed execution engine.
network
low complexity
apache CWE-862
critical
9.1
2020-05-21 CVE-2018-21234 Deserialization of Untrusted Data vulnerability in multiple products
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
network
low complexity
jodd apache CWE-502
critical
9.8
2020-05-20 CVE-2020-1955 Missing Authentication for Critical Function vulnerability in Apache Couchdb 3.0.0
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`.
network
low complexity
apache CWE-306
critical
9.8
2020-05-14 CVE-2020-11973 Deserialization of Untrusted Data vulnerability in multiple products
Apache Camel Netty enables Java deserialization by default.
network
low complexity
apache oracle CWE-502
critical
9.8
2020-05-14 CVE-2020-11972 Deserialization of Untrusted Data vulnerability in multiple products
Apache Camel RabbitMQ enables Java deserialization by default.
network
low complexity
apache oracle CWE-502
critical
9.8
2020-05-14 CVE-2019-17562 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apache Cloudstack
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack.
network
low complexity
apache CWE-119
critical
9.8
2020-05-12 CVE-2020-1939 NULL Pointer Dereference vulnerability in Apache Nuttx
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs.
network
low complexity
apache CWE-476
critical
9.8
2020-05-11 CVE-2018-1285 XXE vulnerability in multiple products
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files.
network
low complexity
apache fedoraproject oracle netapp CWE-611
critical
9.8