Vulnerabilities > Redhat > Jboss Enterprise WEB Platform > 5.1.0

DATE CVE VULNERABILITY TITLE RISK
2014-02-10 CVE-2011-4610 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Redhat products
JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."
network
low complexity
redhat CWE-119
5.0
2012-11-23 CVE-2012-1167 Permissions, Privileges, and Access Controls vulnerability in Redhat products
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
network
high complexity
redhat CWE-264
4.6
2010-12-30 CVE-2010-3862 Improper Input Validation vulnerability in Redhat products
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
network
high complexity
redhat CWE-20
2.6