Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Jboss Operations Network
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4573 1 Redhat 1 Jboss Operations Network 2024-11-21 3.5 LOW N/A
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
CVE-2011-3206 2 Redhat, Rhq-project 2 Jboss Operations Network, Rhq 2024-11-21 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-0737 1 Redhat 1 Jboss Operations Network 2024-11-21 5.2 MEDIUM 8.0 HIGH
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.
CVE-2008-5083 1 Redhat 1 Jboss Operations Network 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.