<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat JBoss Enterprise Application Platform</title>
  <link>https://cvedaily.com/pages/tags/redhat-jboss-eap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/redhat-jboss-eap.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat JBoss Enterprise Application Platform</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-39312 – SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39312</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39312</strong></p>
  <p>SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can crash the vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701), term…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20004 – A vulnerability in the TLS library of Cisco IOS XE Software could allow an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20004</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20004</strong></p>
  <p>A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.  This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be do…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-771</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25075 – strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25075</guid>
    <pubDate>Mon, 23 Mar 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25075</strong></p>
  <p>strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25998 – strongMan is a management interface for strongSwan, an OpenSource IPsec-based VP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25998</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25998</strong></p>
  <p>strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key stream is generated to encrypt the data in the database fields. But because strong…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-323</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25532 – ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25532</guid>
    <pubDate>Wed, 04 Feb 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25532</strong></p>
  <p>ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncated payloads can cause integer underflow during fragment length calculation. When processing EAP-Expanded (WSC) messages, the code computes frag_len b…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1186 – EAP Legislator is vulnerable to Path Traversal in file extraction functionality...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1186</guid>
    <pubDate>Mon, 02 Feb 2026 14:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1186</strong></p>
  <p>EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon opening the file. This issue was fixed in version 2.25a.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62291 – In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62291</guid>
    <pubDate>Fri, 16 Jan 2026 19:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62291</strong></p>
  <p>In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12543 – A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12543</guid>
    <pubDate>Wed, 07 Jan 2026 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12543</strong></p>
  <p>A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessio…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-63292 – Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freeb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63292</guid>
    <pubDate>Mon, 17 Nov 2025 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-63292</strong></p>
  <p>Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over the `FreeWifi_secure` network. During the EAP-Response/Identity exchange, the su…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50159 – Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50159</guid>
    <pubDate>Tue, 12 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50159</strong></p>
  <p>Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24471 – An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24471</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24471</strong></p>
  <p>An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2251 – A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2251</guid>
    <pubDate>Mon, 07 Apr 2025 14:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2251</strong></p>
  <p>A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12369 – A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12369</guid>
    <pubDate>Mon, 09 Dec 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12369</strong></p>
  <p>A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a victim's identity. This is usually done with a Man-in-the-Middle (MitM) or phishing a…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52424 – The IEEE 802.11 standard sometimes enables an adversary to trick a victim into c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52424</guid>
    <pubDate>Fri, 17 May 2024 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52424</strong></p>
  <p>The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-304</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4967 – strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4967</guid>
    <pubDate>Tue, 14 May 2024 11:57:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4967</strong></p>
  <p>strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6236 – A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6236</guid>
    <pubDate>Wed, 10 Apr 2024 01:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6236</strong></p>
  <p>A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log in again since the second tenant is secured with a different OIDC configuration. The underlying issue is in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1233 – A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1233</guid>
    <pubDate>Tue, 09 Apr 2024 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1233</strong></p>
  <p>A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52160 – The implementation of PEAP in wpa_supplicant through 2.10 allows authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52160</guid>
    <pubDate>Thu, 22 Feb 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52160</strong></p>
  <p>The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22250 – Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22250</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22250</strong></p>
  <p>Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-22245 – Arbitrary Authentication Relay and Session Hijack vulnerabilities in the depreca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22245</guid>
    <pubDate>Tue, 20 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-22245</strong></p>
  <p>Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24301 – Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24301</guid>
    <pubDate>Wed, 14 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24301</strong></p>
  <p>Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-24300 – 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24300</guid>
    <pubDate>Wed, 14 Feb 2024 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-24300</strong></p>
  <p>4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1459 – A path traversal vulnerability was found in Undertow. This issue may allow a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1459</guid>
    <pubDate>Mon, 12 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1459</strong></p>
  <p>A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-24</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4503 – An improper initialization vulnerability was found in Galleon. When using Galleo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4503</guid>
    <pubDate>Tue, 06 Feb 2024 09:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4503</strong></p>
  <p>An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3171 – A flaw was found in EAP-7 during deserialization of certain classes, which permi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3171</guid>
    <pubDate>Wed, 27 Dec 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3171</strong></p>
  <p>A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5379 – A flaw was found in Undertow. When an AJP request is sent that exceeds the max-h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5379</guid>
    <pubDate>Tue, 12 Dec 2023 22:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5379</strong></p>
  <p>A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38902 – A command injection vulnerability in RG-EW series home routers and repeaters v.E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38902</guid>
    <pubDate>Thu, 17 Aug 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38902</strong></p>
  <p>A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote d…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34644 – Remote code execution vulnerability in Ruijie Networks Product: RG-EW series hom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34644</guid>
    <pubDate>Mon, 31 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34644</strong></p>
  <p>Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest pr…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28182 – The issue was addressed with improved authentication. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28182</guid>
    <pubDate>Mon, 08 May 2023 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28182</strong></p>
  <p>The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26463 – strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26463</guid>
    <pubDate>Sat, 15 Apr 2023 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26463</strong></p>
  <p>strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate during EAP-TLS. A server is affected only if it loads plugins that implement TLS…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0414 – Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0414</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0414</strong></p>
  <p>Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41860 – In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41860</guid>
    <pubDate>Tue, 17 Jan 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41860</strong></p>
  <p>In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41859 – In freeradius, the EAP-PWD function compute_password_element() leaks information...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41859</guid>
    <pubDate>Tue, 17 Jan 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41859</strong></p>
  <p>In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1319 – A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sendi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1319</guid>
    <pubDate>Wed, 31 Aug 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1319</strong></p>
  <p>A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0866 – This is a concurrency issue that can result in the wrong caller principal being ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0866</guid>
    <pubDate>Tue, 10 May 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0866</strong></p>
  <p>This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field is used by the org.jboss.as.ejb3.security.RunAsPrincipalInterceptor to keep track of the current identity prior to swit…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45079 – In strongSwan before 5.9.5, a malicious responder can send an EAP-Success messag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45079</guid>
    <pubDate>Mon, 31 Jan 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45079</strong></p>
  <p>In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23304 – The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23304</guid>
    <pubDate>Mon, 17 Jan 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23304</strong></p>
  <p>The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20318 – The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20318</guid>
    <pubDate>Thu, 23 Dec 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20318</strong></p>
  <p>The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30302 – Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30302</guid>
    <pubDate>Wed, 20 Oct 2021 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30302</strong></p>
  <p>Improper authentication of EAP WAPI EAPOL frames from unauthenticated user can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-0276 – A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0276</guid>
    <pubDate>Thu, 15 Jul 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-0276</strong></p>
  <p>A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the rad…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14317 – It was found that the issue for security flaw CVE-2019-3805 appeared again in a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14317</guid>
    <pubDate>Wed, 02 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14317</strong></p>
  <p>It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-364</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19343 – A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19343</guid>
    <pubDate>Tue, 23 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19343</strong></p>
  <p>A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14299 – A flaw was found in JBoss EAP, where the authentication configuration is set-up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14299</guid>
    <pubDate>Fri, 16 Oct 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14299</strong></p>
  <p>A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1710 – The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1710</guid>
    <pubDate>Wed, 16 Sep 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1710</strong></p>
  <p>The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14307 – A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions ship...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14307</guid>
    <pubDate>Fri, 24 Jul 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14307</strong></p>
  <p>A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14297 – A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14297</guid>
    <pubDate>Fri, 24 Jul 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14297</strong></p>
  <p>A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12475 – TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12475</guid>
    <pubDate>Mon, 04 May 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12475</strong></p>
  <p>TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17185 – In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17185</guid>
    <pubDate>Sat, 21 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17185</strong></p>
  <p>In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-662</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10064 – hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10064</guid>
    <pubDate>Fri, 28 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10064</strong></p>
  <p>hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-331</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9428 – In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9428</guid>
    <pubDate>Thu, 27 Feb 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9428</strong></p>
  <p>In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8597 – eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8597</guid>
    <pubDate>Mon, 03 Feb 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8597</strong></p>
  <p>eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14885 – A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14885</guid>
    <pubDate>Thu, 23 Jan 2020 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14885</strong></p>
  <p>A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5626 – EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5626</guid>
    <pubDate>Thu, 23 Jan 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5626</strong></p>
  <p>EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14843 – A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14843</guid>
    <pubDate>Tue, 07 Jan 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14843</strong></p>
  <p>A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-592</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15999 – A vulnerability in the application environment of Cisco Data Center Network Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15999</guid>
    <pubDate>Mon, 06 Jan 2020 08:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15999</strong></p>
  <p>A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by au…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0169 – In JBoss EAP 6 a security domain is configured to use a cache that is shared bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0169</guid>
    <pubDate>Thu, 02 Jan 2020 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0169</strong></p>
  <p>In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a secu…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13456 – In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13456</guid>
    <pubDate>Tue, 03 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13456</strong></p>
  <p>In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10202 – A series of deserialization vulnerabilities have been discovered in Codehaus 1.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10202</guid>
    <pubDate>Tue, 01 Oct 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10202</strong></p>
  <p>A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12586 – The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12586</guid>
    <pubDate>Wed, 04 Sep 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12586</strong></p>
  <p>The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12587 – The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12587</guid>
    <pubDate>Wed, 04 Sep 2019 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12587</strong></p>
  <p>The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13377 – The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13377</guid>
    <pubDate>Thu, 15 Aug 2019 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13377</strong></p>
  <p>The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3805 – A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3805</guid>
    <pubDate>Fri, 03 May 2019 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3805</strong></p>
  <p>A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-364</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11555 – The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11555</guid>
    <pubDate>Fri, 26 Apr 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11555</strong></p>
  <p>The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9499 – The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9499</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9499</strong></p>
  <p>The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and includi…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9498 – The implementations of EAP-PWD in hostapd EAP Server, when built against a crypt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9498</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9498</strong></p>
  <p>The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE su…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9497 – The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9497</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9497</strong></p>
  <p>The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key o…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-301</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-9495 – The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9495</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-9495</strong></p>
  <p>The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions o…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15372 – A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15372</guid>
    <pubDate>Fri, 05 Oct 2018 14:29:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15372</strong></p>
  <p>A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected device. The vulnerability is due to a logic error in the affected software. An attacker could explo…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-5393 – The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wirele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5393</guid>
    <pubDate>Fri, 28 Sep 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-5393</strong></p>
  <p>The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8657 – It was discovered that EAP packages in certain versions of Red Hat Enterprise Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8657</guid>
    <pubDate>Tue, 31 Jul 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8657</strong></p>
  <p>It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7464 – It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7464</guid>
    <pubDate>Fri, 27 Jul 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7464</strong></p>
  <p>It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-12167 – It was found in EAP 7 before 7.0.9 that properties based files of the management...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12167</guid>
    <pubDate>Thu, 26 Jul 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-12167</strong></p>
  <p>It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7465 – It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT process...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7465</guid>
    <pubDate>Wed, 27 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7465</strong></p>
  <p>It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a 'javax.xml.transform.TransformerFactory'. If the FEATURE_SECURE_PROCESSING feature is set to 'true', it mitigates thi…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-11574 – Improper input validation together with an integer overflow in the EAP-TLS proto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11574</guid>
    <pubDate>Thu, 14 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-11574</strong></p>
  <p>Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-0277 – A vulnerability in the Extensible Authentication Protocol-Transport Layer Securi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-0277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-0277</guid>
    <pubDate>Thu, 17 May 2018 03:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-0277</strong></p>
  <p>A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incomple…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-0277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-8627 – admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8627</guid>
    <pubDate>Fri, 11 May 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-8627</strong></p>
  <p>admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10168 – TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10168</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10168</strong></p>
  <p>TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10167 – The web application backup file in the TP-Link EAP Controller and Omada Controll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10167</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10167</strong></p>
  <p>The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify the backup file in order to elevate their privileges. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-10166 – The web management interface in the TP-Link EAP Controller and Omada Controller ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10166</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-10166</strong></p>
  <p>The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-10165 – Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10165</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-10165</strong></p>
  <p>Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-10164 – Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10164</guid>
    <pubDate>Thu, 03 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-10164</strong></p>
  <p>Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3626 – The Grails Resource Plugin often has to exchange URIs for resources with other i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3626</guid>
    <pubDate>Mon, 19 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3626</strong></p>
  <p>The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the normalized URI did not step outside the appropriate root directory (e.g. the web application root), decoded the URI and che…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9585 – Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9585</guid>
    <pubDate>Fri, 09 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9585</strong></p>
  <p>Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it. An attacker could exploit this vulnerability resulting in a denial of service attack.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5316 – The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5316</guid>
    <pubDate>Wed, 21 Feb 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5316</strong></p>
  <p>The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5315 – The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5315</guid>
    <pubDate>Wed, 21 Feb 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5315</strong></p>
  <p>The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5314 – The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5314</guid>
    <pubDate>Wed, 21 Feb 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5314</strong></p>
  <p>The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1048 – It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1048</guid>
    <pubDate>Wed, 24 Jan 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1048</strong></p>
  <p>It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12189 – It was discovered that the jboss init script as used in Red Hat JBoss Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12189</guid>
    <pubDate>Wed, 10 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12189</strong></p>
  <p>It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2071 – Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2071</guid>
    <pubDate>Mon, 08 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2071</strong></p>
  <p>Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-12274 – A vulnerability in Extensible Authentication Protocol (EAP) ingress frame proces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12274</guid>
    <pubDate>Thu, 02 Nov 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-12274</strong></p>
  <p>A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (AP) to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of the EAP frame. An attack…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1849 – AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1849</guid>
    <pubDate>Tue, 19 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1849</strong></p>
  <p>AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-13015 – The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-13015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-13015</guid>
    <pubDate>Thu, 14 Sep 2017 06:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-13015</strong></p>
  <p>The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap_print().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-13015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7561 – Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7561</guid>
    <pubDate>Wed, 13 Sep 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7561</strong></p>
  <p>Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6311 – Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6311</guid>
    <pubDate>Tue, 22 Aug 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6311</strong></p>
  <p>Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3690 – The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3690</guid>
    <pubDate>Thu, 08 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3690</strong></p>
  <p>The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-6988 – An issue was discovered in certain Apple products. macOS before 10.12.5 is affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6988</guid>
    <pubDate>Mon, 22 May 2017 05:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-6988</strong></p>
  <p>An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires 802.1X authentication, because EAP-TLS certificate validation mishandles certificate changes.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7503 – It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7503</guid>
    <pubDate>Thu, 18 May 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7503</strong></p>
  <p>It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8764 – Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8764</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8764</strong></p>
  <p>Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-8763 – The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8763</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-8763</strong></p>
  <p>The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8762 – The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8762</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8762</strong></p>
  <p>The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8762">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
