Vulnerabilities > Redhat > Jboss Operations Network > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-14340 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles.
network
redhat oracle
4.3
2020-01-23 CVE-2012-5626 Unspecified vulnerability in Redhat products
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
network
low complexity
redhat
5.0
2019-11-08 CVE-2008-5083 Information Exposure vulnerability in Redhat Jboss Operations Network 2.1.0/2.1.2
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
network
low complexity
redhat CWE-200
4.0
2019-10-30 CVE-2010-0737 Incorrect Permission Assignment for Critical Resource vulnerability in Redhat Jboss Operations Network
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.
low complexity
redhat CWE-732
5.2
2019-10-03 CVE-2019-3834 Unsafe Reflection vulnerability in Redhat Jboss Operations Network
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON).
network
redhat CWE-470
6.8
2016-09-07 CVE-2016-5422 Permissions, Privileges, and Access Controls vulnerability in Redhat Jboss Operations Network
The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.
network
low complexity
redhat CWE-264
6.5
2015-08-11 CVE-2015-3267 Cross-site Scripting vulnerability in Redhat Jboss Operations Network
Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
redhat CWE-79
4.3
2015-02-13 CVE-2014-7853 Information Exposure vulnerability in Redhat products
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
network
low complexity
redhat CWE-200
4.0
2014-02-14 CVE-2012-1100 Improper Authentication vulnerability in Redhat Jboss Operations Network
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credentials are invalid, allows remote attackers to login to LDAP-based accounts via an arbitrary password in a login request.
network
redhat CWE-287
5.8
2014-02-14 CVE-2012-0062 Improper Authentication vulnerability in Redhat Jboss Operations Network
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
network
redhat CWE-287
5.8