Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache jetspeed vulnerabilities and exploits
(subscribe to this query)
6.4
CVSSv2
CVE-2016-2171
The User Manager service in Apache Jetspeed prior to 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote malicious users to (1) add, (2) edit, or (3) delete users via the REST API.
Apache Jetspeed
9
CVSSv2
CVE-2016-0709
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed prior to 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry,...
Apache Jetspeed
1 EDB exploit
4.3
CVSSv2
CVE-2016-0711
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed prior to 2.3.1 allow remote malicious users to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
Apache Jetspeed
4.3
CVSSv2
CVE-2016-0712
Cross-site scripting (XSS) vulnerability in Apache Jetspeed prior to 2.3.1 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to portal.
Apache Jetspeed
7.5
CVSSv2
CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant proje...
Apache Jetspeed
7.5
CVSSv2
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed prior to 2.3.1 allow remote malicious users to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
Apache Jetspeed
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started