Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-13 CVE-2017-12612 Deserialization of Untrusted Data vulnerability in Apache Spark
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket.
local
low complexity
apache CWE-502
7.8
2017-09-13 CVE-2016-8744 Deserialization of Untrusted Data vulnerability in Apache Brooklyn
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs.
network
low complexity
apache CWE-502
8.8
2017-09-13 CVE-2016-8737 Cross-Site Request Forgery (CSRF) vulnerability in Apache Brooklyn
In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logged in to Brooklyn, would cause the server to execute the attacker's commands as the user.
network
low complexity
apache CWE-352
8.8
2017-09-07 CVE-2015-3250 Information Exposure vulnerability in Apache Directory Ldap API 1.0.0
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
network
low complexity
apache CWE-200
7.5
2017-08-30 CVE-2016-4462 Improper Input Validation vulnerability in Apache Ofbiz
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution.
network
low complexity
apache CWE-20
8.8
2017-08-30 CVE-2017-3163 Path Traversal vulnerability in Apache Solr
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name.
network
low complexity
apache CWE-22
7.5
2017-08-29 CVE-2017-3154 Information Exposure vulnerability in Apache Atlas 0.6.0/0.7.0
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
network
low complexity
apache CWE-200
7.5
2017-08-29 CVE-2016-8752 Improper Access Control vulnerability in Apache Atlas 0.6.0/0.7.0/0.7.1
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
network
low complexity
apache CWE-284
7.5
2017-08-29 CVE-2015-5209 Improper Input Validation vulnerability in Apache Struts
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
network
low complexity
apache CWE-20
7.5
2017-08-11 CVE-2017-7675 Path Traversal vulnerability in Apache Tomcat
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks.
network
low complexity
apache CWE-22
7.5