<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:46:25.216049+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318691</id>
    <title>EUVD-2026-318691</title>
    <updated>2026-10-02T19:46:25.233279+00:00</updated>
    <content>EUVD-2026-318691</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2012-4549</id>
    <title>fkie_cve-2012-4549</title>
    <updated>2026-10-02T19:46:25.233319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB methods, leading to unauthorized access to sensitive functionalities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2012-4549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4crg-m9w3-g9fc</id>
    <title>GHSA-4crg-m9w3-g9fc</title>
    <updated>2026-10-02T19:46:25.233353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4crg-m9w3-g9fc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2012-4549</id>
    <title>gsd-2012-4549</title>
    <updated>2026-10-02T19:46:25.233371+00:00</updated>
    <content>gsd-2012-4549</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2012-4549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2012:1591</id>
    <title>RHSA-2012:1591 — Red Hat Security Advisory: JBoss Enterprise Application Platform 6.0.1 update</title>
    <updated>2026-10-02T19:46:25.233383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled apache-cxf: Certain child policies of WS-SecurityPolicy 1.1 SupportingToken policy not applied on the client side apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token Mojarra: deployed web applications can read FacesContext from other applications under certain conditions httpd: mod_negotiation XSS via untrusted file names in directories with MultiViews enabled JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains apache-cxf: SOAPAction spoofing on document literal web services JBoss Enterprise Application Platform: org.jboss.as.ejb3: JBoss Enterprise Application Platform: Access restriction bypass via improper EJB method authorization JBoss Enterprise Application Platform: JBoss EAP: JBEAP: JBoss Enterprise Application Platform: Unauthorized EJB access via authorization module bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2012:1591"/>
  </entry>
</feed>
