CVE Tools

Red Hat Jboss A-mq

21 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Jboss A-mq, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Jboss A-mq CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Jboss A-mq CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High210%
  • Medium1886%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Jboss A-mq.

  1. CVE-2022-4245Codehaus-plexus: xml external entity (xxe) injection4.3
  2. CVE-2023-34462netty-handler SniHandler 16MB allocation6.5
  3. CVE-2023-35116jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that ...4.7
  4. CVE-2023-1664A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak....6.5
  5. CVE-2023-20861In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression ...6.5
  6. CVE-2022-24823Local Information Disclosure Vulnerability in io.netty:netty-codec-http5.5
  7. CVE-2022-25647Deserialization of Untrusted Data7.7
  8. CVE-2020-36518jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.7.5
  9. CVE-2021-43797HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling6.5
  10. CVE-2021-21348XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)5.3
  11. CVE-2021-21349A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host6.1
  12. CVE-2021-21350XStream is vulnerable to an Arbitrary Code Execution attack5.3
  13. CVE-2021-21351XStream is vulnerable to an Arbitrary Code Execution attack5.4
  14. CVE-2021-21342A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host5.3
  15. CVE-2021-21344XStream is vulnerable to an Arbitrary Code Execution attack5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store