Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-02-06 CVE-2016-6813 Unspecified vulnerability in Apache Cloudstack
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API.
network
low complexity
apache
critical
9.8
2018-01-24 CVE-2017-15718 Unspecified vulnerability in Apache Hadoop 2.7.3/2.7.4
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
network
low complexity
apache
critical
9.8
2018-01-23 CVE-2017-15697 Improper Input Validation vulnerability in Apache Nifi
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution.
network
low complexity
apache CWE-20
critical
9.8
2018-01-18 CVE-2016-6814 Deserialization of Untrusted Data vulnerability in multiple products
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g.
network
low complexity
apache redhat CWE-502
critical
9.8
2018-01-04 CVE-2017-15714 Injection vulnerability in Apache Ofbiz 16.11.01/16.11.02/16.11.03
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed.
network
low complexity
apache CWE-74
critical
9.8
2017-12-28 CVE-2017-5641 Deserialization of Untrusted Data vulnerability in multiple products
Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default.
network
low complexity
apache hp CWE-502
critical
9.8
2017-12-11 CVE-2017-15708 Injection vulnerability in multiple products
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI).
network
low complexity
apache oracle CWE-74
critical
9.8
2017-12-01 CVE-2017-15702 Unspecified vulnerability in Apache Qpid Broker-J
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port.
network
low complexity
apache
critical
9.8
2017-11-15 CVE-2017-12634 Deserialization of Untrusted Data vulnerability in Apache Camel
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability.
network
low complexity
apache CWE-502
critical
9.8
2017-11-15 CVE-2017-12633 Deserialization of Untrusted Data vulnerability in Apache Camel
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability.
network
low complexity
apache CWE-502
critical
9.8