<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat JBoss Enterprise Application Platform (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/redhat-jboss-eap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/redhat-jboss-eap-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat JBoss Enterprise Application Platform (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-39312 – SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39312</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39312</strong></p>
  <p>SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can crash the vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701), term…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20004 – A vulnerability in the TLS library of Cisco IOS XE Software could allow an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20004</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20004</strong></p>
  <p>A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.  This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be do…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-771</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25075 – strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25075</guid>
    <pubDate>Mon, 23 Mar 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25075</strong></p>
  <p>strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25998 – strongMan is a management interface for strongSwan, an OpenSource IPsec-based VP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25998</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25998</strong></p>
  <p>strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key stream is generated to encrypt the data in the database fields. But because strong…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-323</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1186 – EAP Legislator is vulnerable to Path Traversal in file extraction functionality...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1186</guid>
    <pubDate>Mon, 02 Feb 2026 14:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1186</strong></p>
  <p>EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon opening the file. This issue was fixed in version 2.25a.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62291 – In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62291</guid>
    <pubDate>Fri, 16 Jan 2026 19:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62291</strong></p>
  <p>In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12543 – A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12543</guid>
    <pubDate>Wed, 07 Jan 2026 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12543</strong></p>
  <p>A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessio…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50159 – Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50159</guid>
    <pubDate>Tue, 12 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50159</strong></p>
  <p>Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52424 – The IEEE 802.11 standard sometimes enables an adversary to trick a victim into c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52424</guid>
    <pubDate>Fri, 17 May 2024 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52424</strong></p>
  <p>The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-304</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4967 – strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4967</guid>
    <pubDate>Tue, 14 May 2024 11:57:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4967</strong></p>
  <p>strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6236 – A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6236</guid>
    <pubDate>Wed, 10 Apr 2024 01:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6236</strong></p>
  <p>A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log in again since the second tenant is secured with a different OIDC configuration. The underlying issue is in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1233 – A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1233</guid>
    <pubDate>Tue, 09 Apr 2024 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1233</strong></p>
  <p>A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22250 – Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22250</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22250</strong></p>
  <p>Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22245 – Arbitrary Authentication Relay and Session Hijack vulnerabilities in the depreca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22245</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22245</strong></p>
  <p>Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24301 – Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24301</guid>
    <pubDate>Wed, 14 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24301</strong></p>
  <p>Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-24300 – 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24300</guid>
    <pubDate>Wed, 14 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-24300</strong></p>
  <p>4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3171 – A flaw was found in EAP-7 during deserialization of certain classes, which permi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3171</guid>
    <pubDate>Wed, 27 Dec 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3171</strong></p>
  <p>A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5379 – A flaw was found in Undertow. When an AJP request is sent that exceeds the max-h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5379</guid>
    <pubDate>Tue, 12 Dec 2023 22:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5379</strong></p>
  <p>A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38902 – A command injection vulnerability in RG-EW series home routers and repeaters v.E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38902</guid>
    <pubDate>Thu, 17 Aug 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38902</strong></p>
  <p>A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote d…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34644 – Remote code execution vulnerability in Ruijie Networks Product: RG-EW series hom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34644</guid>
    <pubDate>Mon, 31 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34644</strong></p>
  <p>Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest pr…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26463 – strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26463</guid>
    <pubDate>Sat, 15 Apr 2023 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26463</strong></p>
  <p>strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate during EAP-TLS. A server is affected only if it loads plugins that implement TLS…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41860 – In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41860</guid>
    <pubDate>Tue, 17 Jan 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41860</strong></p>
  <p>In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41859 – In freeradius, the EAP-PWD function compute_password_element() leaks information...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41859</guid>
    <pubDate>Tue, 17 Jan 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41859</strong></p>
  <p>In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1319 – A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sendi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1319</guid>
    <pubDate>Wed, 31 Aug 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1319</strong></p>
  <p>A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45079 – In strongSwan before 5.9.5, a malicious responder can send an EAP-Success messag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45079</guid>
    <pubDate>Mon, 31 Jan 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45079</strong></p>
  <p>In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23304 – The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23304</guid>
    <pubDate>Mon, 17 Jan 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23304</strong></p>
  <p>The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20318 – The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20318</guid>
    <pubDate>Thu, 23 Dec 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20318</strong></p>
  <p>The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30302 – Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30302</guid>
    <pubDate>Wed, 20 Oct 2021 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30302</strong></p>
  <p>Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-0276 – A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0276</guid>
    <pubDate>Thu, 15 Jul 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-0276</strong></p>
  <p>A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the rad…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19343 – A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19343</guid>
    <pubDate>Tue, 23 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19343</strong></p>
  <p>A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17185 – In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17185</guid>
    <pubDate>Sat, 21 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17185</strong></p>
  <p>In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-662</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10064 – hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10064</guid>
    <pubDate>Fri, 28 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10064</strong></p>
  <p>hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9428 – In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9428</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9428</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8597 – eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8597</guid>
    <pubDate>Mon, 03 Feb 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8597</strong></p>
  <p>eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5626 – EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5626</guid>
    <pubDate>Thu, 23 Jan 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5626</strong></p>
  <p>EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14843 – A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14843</guid>
    <pubDate>Tue, 07 Jan 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14843</strong></p>
  <p>A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-592</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10202 – A series of deserialization vulnerabilities have been discovered in Codehaus 1.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10202</guid>
    <pubDate>Tue, 01 Oct 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10202</strong></p>
  <p>A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12587 – The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12587</guid>
    <pubDate>Wed, 04 Sep 2019 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12587</strong></p>
  <p>The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9499 – The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9499</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9499</strong></p>
  <p>The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and includi…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9498 – The implementations of EAP-PWD in hostapd EAP Server, when built against a crypt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9498</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9498</strong></p>
  <p>The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE su…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9497 – The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9497</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9497</strong></p>
  <p>The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key o…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-301</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15372 – A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15372</guid>
    <pubDate>Fri, 05 Oct 2018 14:29:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15372</strong></p>
  <p>A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected device. The vulnerability is due to a logic error in the affected software. An attacker could explo…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-5393 – The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wirele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5393</guid>
    <pubDate>Fri, 28 Sep 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-5393</strong></p>
  <p>The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8657 – It was discovered that EAP packages in certain versions of Red Hat Enterprise Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8657</guid>
    <pubDate>Tue, 31 Jul 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8657</strong></p>
  <p>It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7464 – It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7464</guid>
    <pubDate>Fri, 27 Jul 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7464</strong></p>
  <p>It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7465 – It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT process...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7465</guid>
    <pubDate>Wed, 27 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7465</strong></p>
  <p>It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a 'javax.xml.transform.TransformerFactory'. If the FEATURE_SECURE_PROCESSING feature is set to 'true', it mitigates thi…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11574 – Improper input validation together with an integer overflow in the EAP-TLS proto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11574</guid>
    <pubDate>Thu, 14 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11574</strong></p>
  <p>Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-0277 – A vulnerability in the Extensible Authentication Protocol-Transport Layer Securi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-0277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-0277</guid>
    <pubDate>Thu, 17 May 2018 03:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-0277</strong></p>
  <p>A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incomple…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-0277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10168 – TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10168</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10168</strong></p>
  <p>TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10167 – The web application backup file in the TP-Link EAP Controller and Omada Controll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10167</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10167</strong></p>
  <p>The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify the backup file in order to elevate their privileges. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10166 – The web management interface in the TP-Link EAP Controller and Omada Controller ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10166</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10166</strong></p>
  <p>The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3626 – The Grails Resource Plugin often has to exchange URIs for resources with other i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3626</guid>
    <pubDate>Mon, 19 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3626</strong></p>
  <p>The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the normalized URI did not step outside the appropriate root directory (e.g. the web application root), decoded the URI and che…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1048 – It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1048</guid>
    <pubDate>Wed, 24 Jan 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1048</strong></p>
  <p>It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12189 – It was discovered that the jboss init script as used in Red Hat JBoss Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12189</guid>
    <pubDate>Wed, 10 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12189</strong></p>
  <p>It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2071 – Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2071</guid>
    <pubDate>Mon, 08 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2071</strong></p>
  <p>Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-13015 – The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-13015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-13015</guid>
    <pubDate>Thu, 14 Sep 2017 06:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-13015</strong></p>
  <p>The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap_print().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-13015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7561 – Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7561</guid>
    <pubDate>Wed, 13 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7561</strong></p>
  <p>Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3690 – The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3690</guid>
    <pubDate>Thu, 08 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3690</strong></p>
  <p>The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7503 – It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7503</guid>
    <pubDate>Thu, 18 May 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7503</strong></p>
  <p>It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8764 – Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8764</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8764</strong></p>
  <p>Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8763 – The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8763</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8763</strong></p>
  <p>The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7065 – The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7065</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7065</strong></p>
  <p>The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5406 – The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5406</guid>
    <pubDate>Mon, 26 Sep 2016 14:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5406</strong></p>
  <p>The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6669 – Buffer overflow in the Authentication, Authorization and Accounting (AAA) module...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6669</guid>
    <pubDate>Thu, 22 Sep 2016 15:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6669</strong></p>
  <p>Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitrary code by sending a crafted EAP packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-7998 – Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7998</guid>
    <pubDate>Sat, 15 Nov 2014 02:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-7998</strong></p>
  <p>Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3490 – RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3490</guid>
    <pubDate>Tue, 19 Aug 2014 18:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3490</strong></p>
  <p>RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3530 – The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3530</guid>
    <pubDate>Tue, 22 Jul 2014 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3530</strong></p>
  <p>The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2185 – The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2185</guid>
    <pubDate>Sun, 19 Jan 2014 18:02:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2185</strong></p>
  <p>The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186.  NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-3466 – The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3466</guid>
    <pubDate>Thu, 29 Aug 2013 12:07:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-3466</strong></p>
  <p>The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2165 – ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2165</guid>
    <pubDate>Tue, 23 Jul 2013 11:03:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2165</strong></p>
  <p>ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss SOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal through 4.3 CP07 and 5.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5629 – The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5629</guid>
    <pubDate>Tue, 12 Mar 2013 23:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5629</strong></p>
  <p>The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3708 – The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise App...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3708</guid>
    <pubDate>Thu, 30 Dec 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3708</strong></p>
  <p>The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of class files, which allows remote attackers to execute arbitrary code via a crafted static initializer.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1428 – The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Applica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1428</guid>
    <pubDate>Wed, 28 Apr 2010 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1428</strong></p>
  <p>The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0524 – The default configuration of the FreeRADIUS server in Apple Mac OS X Server befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0524</guid>
    <pubDate>Tue, 30 Mar 2010 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0524</strong></p>
  <p>The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5563 – Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.x, 3.1.x, 3.2.x, 3.3.1.x, and 3.3.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5563</guid>
    <pubDate>Mon, 15 Dec 2008 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5563</strong></p>
  <p>Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.x, 3.1.x, 3.2.x, 3.3.1.x, and 3.3.2.x allows remote attackers to cause a denial of service (device crash) via a malformed Extensible Authentication Protocol (EAP) frame.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2441 – Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2441</guid>
    <pubDate>Thu, 04 Sep 2008 16:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2441</strong></p>
  <p>Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote authenticated users to cause a denial of service (CSRadius and CSAuth service crash) or possibly execute arbitrary co…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5651 – Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5651</guid>
    <pubDate>Tue, 23 Oct 2007 21:47:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5651</strong></p>
  <p>Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP devices), IOS 12.1 and 12.2 on Cisco switches (Wired EAP devices), and CatOS 6.x through 8.x on Cisco switches allows remote attackers to cause a denial of service (device reload) via a crafted EAP Response Identity pack…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-5601 – Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplican...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5601</guid>
    <pubDate>Sat, 28 Oct 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-5601</strong></p>
  <p>Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-1354 – Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1354</guid>
    <pubDate>Wed, 22 Mar 2006 02:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-1354</strong></p>
  <p>Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-1099 – Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1099</guid>
    <pubDate>Mon, 10 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-1099</strong></p>
  <p>Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1099">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
