imPC@ndo EN

Vulnerabilità Apache

3261 CVE

CVE-2010-0425
Alta 10.0

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dl…

apache http_server · broadcom vmware_ace_management_server · ibm http_server · ibm websphere_application_server · e altri 1
0.94EPSS
CVE-2018-1335
Alta 8.1

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a ser…

apache tika
0.94EPSS
CVE-2021-27850
Critica 9.8

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before…

apache tapestry
0.94EPSS
CVE-2013-1965
Alta 9.3

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

apache struts · apache struts2-showcase
0.93EPSS
CVE-2024-45507
Critica 9.8

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

apache ofbiz
0.93EPSS
CVE-2023-48795
Media 5.9

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server …

9bis kitty · apache sshd · apache sshj · apple macos · e altri 64
0.93EPSS
CVE-2021-27905
Critica 9.8

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the loca…

apache solr
0.93EPSS
CVE-2016-3081
Alta 8.1

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

apache struts · oracle siebel_e-billing
0.93EPSS
CVE-2019-0227
Alta 7.5

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from sou…

apache axis · oracle agile_engineering_data_management · oracle agile_product_lifecycle_management · oracle application_testing_suite · e altri 33
0.92EPSS
CVE-2017-12629
Critica 9.8

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnera…

apache solr · canonical ubuntu_linux · debian debian_linux · redhat jboss_enterprise_application_platform
0.92EPSS
CVE-2024-27316
Alta 7.5

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

apache http_server · fedoraproject fedora · netapp ontap
0.91EPSS
CVE-2010-1870
Media 5.0

The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects …

apache struts
0.91EPSS
CVE-2024-45216
Critica 9.8

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, w…

apache solr
0.91EPSS
CVE-2007-0450
Media 5.0

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with comb…

apache http_server · apache tomcat
0.91EPSS
CVE-2011-3368
Media 5.0

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows…

apache http_server
0.91EPSS
CVE-2018-11759
Alta 7.5

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by …

apache tomcat_jk_connector · debian debian_linux · redhat jboss_core_services
0.91EPSS
CVE-2017-12636
Alta 7.2

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 …

apache couchdb
0.91EPSS
CVE-2023-37582
Critica 9.8

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can e…

apache rocketmq
0.90EPSS
CVE-2022-30522
Alta 7.5

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.90EPSS
CVE-2020-11984
Critica 9.8

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 9
0.90EPSS
CVE-2010-0219
Alta 10.0

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a…

apache axis2 · sap businessobjects
0.90EPSS
CVE-2020-9490
Alta 7.5

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push of…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 21
0.90EPSS
CVE-2017-5645
Critica 9.8

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

apache log4j · netapp oncommand_api_services · netapp oncommand_insight · netapp oncommand_workflow_automation · e altri 75
0.89EPSS
CVE-2021-45456
Critica 9.8

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may c…

apache kylin
0.89EPSS
CVE-2011-3923
Critica 9.8

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

apache struts · redhat jboss_enterprise_web_server
0.88EPSS