|
265171
|
6.5 |
MEDIUM
Network
|
apache
|
ranger
|
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
|
CWE-255
Credentials Management
|
CVE-2016-6815
|
2024-11-21 11:56 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265172
|
8.8 |
HIGH
Network
|
apache
|
wicket
|
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTT…
|
CWE-352
Origin Validation Error
|
CVE-2016-6806
|
2024-11-21 11:56 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265173
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on…
|
CWE-22
Path Traversal
|
CVE-2016-6795
|
2024-11-21 11:56 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265174
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6800
|
2024-11-21 11:56 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265175
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6817
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265176
|
7.5 |
HIGH
Network
|
apache debian netapp canonical oracle redhat
|
tomcat debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux tekelec_platform_distribution enterprise_linux_desktop enterprise_linux_workstation
|
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via…
|
NVD-CWE-noinfo
|
CVE-2016-6796
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265177
|
7.5 |
HIGH
Network
|
apache oracle debian netapp canonical redhat
|
tomcat tekelec_platform_distribution debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation
|
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global J…
|
CWE-863
Incorrect Authorization
|
CVE-2016-6797
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265178
|
6.1 |
MEDIUM
Network
|
apache
|
cxf
|
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the availa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6812
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265179
|
5.3 |
MEDIUM
Network
|
apache debian redhat netapp canonical oracle
|
tomcat debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server jboss_enterprise_web_server enterprise_linux_eus enterprise_linux_server_tus …
|
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.R…
|
NVD-CWE-noinfo
|
CVE-2016-6794
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265180
|
9.8 |
CRITICAL
Network
|
apache
|
sling
|
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts whic…
|
CWE-611
XXE
|
CVE-2016-6798
|
2024-11-21 11:56 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|