Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-06 CVE-2016-5004 Resource Exhaustion vulnerability in Apache Ws-Xmlrpc 3.1.3
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
network
low complexity
apache CWE-400
6.5
2017-05-26 CVE-2017-5646 Origin Validation Error vulnerability in Apache Knox
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox.
network
high complexity
apache CWE-346
6.8
2017-05-19 CVE-2015-5241 Open Redirect vulnerability in Apache Juddi
After logging into the portal, the logout jsp page redirects the browser back to the login page after.
network
low complexity
apache CWE-601
6.1
2017-05-15 CVE-2017-5655 Information Exposure vulnerability in Apache Ambari
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host.
network
low complexity
apache CWE-200
6.5
2017-05-02 CVE-2016-4467 Improper Certificate Validation vulnerability in Apache Qpid Proton
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.
network
high complexity
apache CWE-295
5.9
2017-04-26 CVE-2017-3161 Cross-site Scripting vulnerability in Apache Hadoop
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
network
low complexity
apache CWE-79
6.1
2017-04-18 CVE-2017-5653 Improper Certificate Validation vulnerability in Apache CXF
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
network
low complexity
apache CWE-295
5.3
2017-04-07 CVE-2016-6805 XXE vulnerability in Apache Ignite
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
network
high complexity
apache CWE-611
5.9
2017-03-29 CVE-2016-4976 Information Exposure vulnerability in Apache Ambari
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
local
low complexity
apache CWE-200
5.5
2017-03-24 CVE-2017-5644 XML Entity Expansion vulnerability in Apache POI
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
local
low complexity
apache CWE-776
5.5