Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
java vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2010-5326
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly prior to 7.3, does not require authentication, which allows remote malicious users to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "D...
Sap Netweaver Application Server Java
1 Article
10
CVSSv2
CVE-2016-1998
HPE Service Manager (SM) 9.3x prior to 9.35 P4 and 9.4x prior to 9.41.P2 allows remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Hp Service Manager 9.31
Hp Service Manager 9.33
Hp Service Manager 9.41
Hp Service Manager 9.40
Hp Service Manager 9.32
Hp Service Manager 9.35
Hp Service Manager 9.30
Hp Service Manager 9.34
10
CVSSv2
CVE-2016-1997
HPE Operations Orchestration 10.x prior to 10.51 and Operations Orchestration content prior to 1.7.0 allow remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Hp Operations Orchestration Content
Hp Operations Orchestration 10.20
Hp Operations Orchestration 10.22
Hp Operations Orchestration 10.50
Hp Operations Orchestration 10.22.1
Hp Operations Orchestration 10.01
Hp Operations Orchestration 10.02
Hp Operations Orchestration 10.0
Hp Operations Orchestration 10.10
Hp Operations Orchestration 10.21
10
CVSSv2
CVE-2016-2397
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote malicious users to deserialize and execute arbitrary Java code via crafted XML data.
Sonicwall Uma Em5000 Firmware 8.0
Sonicwall Uma Em5000 Firmware 8.1
Sonicwall Uma Em5000 Firmware 7.2
Sonicwall Global Management System 7.2
Sonicwall Global Management System 8.0
Sonicwall Global Management System 8.1
Sonicwall Analyzer 8.0
Sonicwall Analyzer 7.2
Sonicwall Analyzer 8.1
10
CVSSv2
CVE-2016-1985
HPE Operations Manager 8.x and 9.0 on Windows allows remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
Hp Operations Manager 9.0
Hp Operations Manager 8.1
Hp Operations Manager 8.16
Hp Operations Manager 8.10
10
CVSSv2
CVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote malicious users to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the ...
Ibm Tivoli Common Reporting 3.1.2
Ibm Tivoli Common Reporting 3.1.0.2
Ibm Tivoli Common Reporting 3.1.0.1
Ibm Tivoli Common Reporting 3.1
Ibm Tivoli Common Reporting 3.1.2.1
Ibm Tivoli Common Reporting 2.1
Ibm Tivoli Common Reporting 2.1.1.2
Ibm Tivoli Common Reporting 2.1.1
1 EDB exploit
10
CVSSv2
CVE-2015-7912
The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate prior to 5.30.06 allows remote malicious users to upload and execute arbitrary Java code via a crafted XML document.
Tibbo Aggregate
10
CVSSv2
CVE-2014-8873
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote malicious users to execute arbitrary code via a JAR file.
Oracle Openjdk 1.7.0
10
CVSSv2
CVE-2015-2342
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote malicious users to execute arbitrary code via the RMI protocol.
Vmware Vcenter Server 5.5
Vmware Vcenter Server 6.0
Vmware Vcenter Server 5.0
Vmware Vcenter Server 5.1
1 EDB exploit
1 Github repository
1 Article
10
CVSSv2
CVE-2015-0545
EMC Unisphere for VMAX 8.x prior to 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote malicious users to execute arbitrary code via unspecified vectors.
Emc Unisphere 8.0.0
Emc Unisphere 8.0.1
Emc Unisphere 8.0.2
Emc Unisphere 8.0.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »