<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:59:18 +0000</lastBuildDate>
    <item>
      <title>certa-2013-avi-096 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;JBoss Enterprise Application Platf…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2013-avi-096</link>
      <description>certa-2013-avi-096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2013-avi-096</guid>
    </item>
    <item>
      <title>EUVD-2026-110031</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-110031</link>
      <description>EUVD-2026-110031</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-110031</guid>
    </item>
    <item>
      <title>fkie_cve-2012-0874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-0874</link>
      <description>&lt;p&gt;The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors.  NOTE: this issue can only be exploited when the interceptor is not properly configured with a &amp;#34;second layer of authentication,&amp;#34; or when used in conjunction with other vulnerabilities that bypass this second layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors.  NOTE: this issue can only be exploited when the interceptor is not properly configured with a &amp;#34;second layer of authentication,&amp;#34; or when used in conjunction with other vulnerabilities that bypass this second layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-0874</guid>
    </item>
    <item>
      <title>GHSA-cjrh-9rp2-h6f2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cjrh-9rp2-h6f2</link>
      <description>&lt;p&gt;The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors.  NOTE: this issue can only be exploited when the interceptor is not properly configured with a &amp;#34;second layer of authentication,&amp;#34; or when used in conjunction with other vulnerabilities that bypass this second layer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors.  NOTE: this issue can only be exploited when the interceptor is not properly configured with a &amp;#34;second layer of authentication,&amp;#34; or when used in conjunction with other vulnerabilities that bypass this second layer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cjrh-9rp2-h6f2</guid>
    </item>
    <item>
      <title>gsd-2012-0874</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-0874</link>
      <description>gsd-2012-0874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-0874</guid>
    </item>
    <item>
      <title>RHSA-2013:0191 — Red Hat Security Advisory: JBoss Enterprise Application Platform 5.2.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0191</link>
      <description>&lt;p&gt;JBoss: twiddle.sh accepts credentials as command line arguments, exposing them to other local users via a process listing jbossws: Prone to character encoding pattern attack (XML Encryption flaw) jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key Framework: Information (internal server information, classpath, local working directories, session IDs) disclosure CSRF on jmx-console allows invocation of operations on mbeans Console: XSS in invoke operation Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs JBoss invoker servlets do not require authentication JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided Web: Bypass of security constraints JBoss: AuthorizationInterceptor allows JMX operation to proceed despite authorization failure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JBoss: twiddle.sh accepts credentials as command line arguments, exposing them to other local users via a process listing jbossws: Prone to character encoding pattern attack (XML Encryption flaw) jbossws: Prone to Bleichenbacher attack against to be distributed symmetric key Framework: Information (internal server information, classpath, local working directories, session IDs) disclosure CSRF on jmx-console allows invocation of operations on mbeans Console: XSS in invoke operation Cache: NonManagedConnectionFactory will log password in clear text when an exception occurs JBoss invoker servlets do not require authentication JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started apache-cxf: Apache CXF does not verify that elements were signed / encrypted by a particular Supporting Token JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided Web: Bypass of security constraints JBoss: AuthorizationInterceptor allows JMX operation to proceed despite authorization failure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0191</guid>
    </item>
  </channel>
</rss>
