Vulnerabilities > Redhat > Jboss Operations Network > 3.1.1

DATE CVE VULNERABILITY TITLE RISK
2016-09-27 CVE-2016-6330 Deserialization of Untrusted Data vulnerability in Redhat Jboss Operations Network
The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
network
low complexity
redhat CWE-502
critical
9.8
2016-09-07 CVE-2016-5422 Permissions, Privileges, and Access Controls vulnerability in Redhat Jboss Operations Network
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.
network
low complexity
redhat CWE-264
6.5
2016-08-02 CVE-2016-3737 Improper Input Validation vulnerability in Redhat Jboss Operations Network
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.
network
low complexity
redhat CWE-20
critical
9.0
2015-08-11 CVE-2015-3267 Cross-site Scripting vulnerability in Redhat Jboss Operations Network
Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
redhat CWE-79
4.3