CVE Tools

Jboss Middleware Text-only Advisories

9 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Jboss Middleware Text-only Advisories, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Jboss Middleware Text-only Advisories CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Jboss Middleware Text-only Advisories CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical111%
  • High556%
  • Medium333%

Latest CVEs

The 9 most recently published vulnerabilities affecting Jboss Middleware Text-only Advisories.

  1. CVE-2024-1132Keycloak: path transversal in redirection validation8.1
  2. CVE-2023-4853Quarkus: http security policy bypass8.1
  3. CVE-2022-1415Drools: unsafe data deserialization in streamutils8.1
  4. CVE-2019-14900A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is ...6.5
  5. CVE-2011-2487The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.5.9
  6. CVE-2019-14439A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally...7.5
  7. CVE-2018-1288In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request ...5.4
  8. CVE-2016-4970handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).7.5
  9. CVE-2016-4437Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an u...9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store