<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:08:20 +0000</lastBuildDate>
    <item>
      <title>certa-2011-avi-703 — Plusieurs vulnérabilités affectent JBoss. Elles permettent de contourner
la politique de sécurité du serveur ou de réal…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2011-avi-703</link>
      <description>certa-2011-avi-703</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2011-avi-703</guid>
    </item>
    <item>
      <title>EUVD-2026-116660</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-116660</link>
      <description>EUVD-2026-116660</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-116660</guid>
    </item>
    <item>
      <title>fkie_cve-2011-4085</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2011-4085</link>
      <description>&lt;p&gt;The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method.  NOTE: this vulnerability exists because of a CVE-2010-0738 regression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method.  NOTE: this vulnerability exists because of a CVE-2010-0738 regression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2011-4085</guid>
    </item>
    <item>
      <title>GHSA-24wp-35x7-5hx9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-24wp-35x7-5hx9</link>
      <description>&lt;p&gt;The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method.  NOTE: this vulnerability exists because of a CVE-2010-0738 regression.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method.  NOTE: this vulnerability exists because of a CVE-2010-0738 regression.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-24wp-35x7-5hx9</guid>
    </item>
    <item>
      <title>gsd-2011-4085</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2011-4085</link>
      <description>gsd-2011-4085</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2011-4085</guid>
    </item>
    <item>
      <title>RHSA-2011:1456 — Red Hat Security Advisory: JBoss Enterprise SOA Platform 5.2.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2011:1456</link>
      <description>&lt;p&gt;jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences Invoker servlets authentication bypass (HTTP verb tampering)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences Invoker servlets authentication bypass (HTTP verb tampering)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2011:1456</guid>
    </item>
  </channel>
</rss>
