Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2017-09-25 CVE-2015-7544 Injection vulnerability in Redhat Enterprise Virtualization Manager 3.4/3.4.1/3.5.0
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
network
low complexity
redhat CWE-74
critical
9.1
2017-09-25 CVE-2015-5184 Unspecified vulnerability in Redhat AMQ and Jboss Enterprise web Server
Console: CORS headers set to allow all in Red Hat AMQ.
network
low complexity
redhat
7.5
2017-09-25 CVE-2015-5183 Unspecified vulnerability in Redhat Amq, Jboss A-Mq and Jboss Enterprise web Server
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
network
low complexity
redhat
7.5
2017-09-25 CVE-2015-5182 Cross-Site Request Forgery (CSRF) vulnerability in Redhat AMQ
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
network
low complexity
redhat CWE-352
8.8
2017-09-25 CVE-2015-5181 Cross-site Scripting vulnerability in Redhat Jboss A-Mq
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
network
low complexity
redhat CWE-79
5.4
2017-09-20 CVE-2015-5248 Improper Input Validation vulnerability in Redhat Feedhenry Enterprise Mobile Application Platform
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
network
low complexity
redhat CWE-20
6.5
2017-09-19 CVE-2015-1849 Information Exposure vulnerability in Redhat Jboss Enterprise Application Platform
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.
network
high complexity
redhat CWE-200
5.9
2017-09-19 CVE-2015-7837 7PK - Security Features vulnerability in Redhat products
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
local
low complexity
redhat CWE-254
5.5
2017-09-19 CVE-2014-8174 Information Exposure vulnerability in Redhat Edeploy
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
network
low complexity
redhat CWE-200
critical
9.8
2017-09-19 CVE-2017-12615 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
network
high complexity
apache netapp redhat CWE-434
8.1