Where
-Infinity
0
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Angular.js is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

1 / 3
First published (updated )
Severity
3.3
Infoleak
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

1 / 2
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.

1 / 2
First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Knockout is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

First published (updated )
Severity
8.8
Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.

1 / 3

Remedy

There is currently no known mitigation for this issue.
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality.

1 / 2
Source: MITRE
First published (updated )
Path Traversal

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.12.1 serves as an update to Red Hat Decision Manager 7.12.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): commons-io: apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 (CVE-2021-29425) jdom: XXE allows attackers to cause a DoS via a crafted HTTP request (CVE-2021-33813) logback-classic: logback: remote code execution through JNDI call from within its configuration file (CVE-2021-42550) netty: Information disclosure via the local system temporary directory (CVE-2021-21290) springframework: malicious input leads to insertion of additional log entries (CVE-2021-22096) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.9.1 serves as an update to Red Hat Decision Manager 7.9.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): xstream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
XSS

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.8.0 serves as an update to Red Hat Decision Manager 7.7.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): netty: HTTP request smuggling (CVE-2019-20444) netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers (CVE-2019-16869) netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling (CVE-2020-7238) netty: HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518) netty: HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514) netty: HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512) netty: HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515) netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header (CVE-2019-20445) cxf-core: cxf: does not restrict the number of message attachments (CVE-2019-12406) cxf-core: cxf: OpenId Connect token service does not properly validate the clientId (CVE-2019-12423) cxf-core: cxf: reflected XSS in the services listing page (CVE-2019-17573) jackson-databind: lacks certain net.sf.ehcache blocking (CVE-2019-20330) jackson-databind: Lacks certain xbean-reflect/JNDI blocking (CVE-2020-8840) jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10672) jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10673) jackson-databind: Serialization gadgets in anteros-core (CVE-2020-9548) jackson-databind: Serialization gadgets in commons-jelly:commons-jelly (CVE-2020-11620) jackson-databind: Serialization gadgets in ibatis-sqlmap (CVE-2020-9547) jackson-databind: Serialization gadgets in javax.swing.JEditorPane (CVE-2020-10969) jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider..RmiProvider (CVE-2020-10968) jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactory (CVE-2020-11111) jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProvider (CVE-2020-11112) jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime (CVE-2020-11113) jackson-databind: Serialization gadgets in org.springframework:spring-aop (CVE-2020-11619) jackson-databind: Serialization gadgets in shaded-hikari-config (CVE-2020-9546) jackson-databind: serialization in oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (CVE-2020-14060) jackson-databind: serialization in weblogic/oracle-aqjms (CVE-2020-14061) jackson-databind: serialization in com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (CVE-2020-14062) netty: compression/decompression codecs don't enforce limits on buffer allocation sizes (CVE-2020-11612) quartz: libquartz: XXE attacks via job description (CVE-2019-13990) keycloak: security issue on reset credential flow (CVE-2020-1718) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model &amp; Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. <br>This release of Red Hat Decision Manager 7.7.0 serves as an update to Red Hat Decision Manager 7.6.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> commons-beanutils: apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)</li> <li> elasticsearch: Improper permission issue when attaching a new name to an index (CVE-2019-7611)</li> <li> jackson-databind: polymorphic typing issue related to com.zaxxer.hikari.HikariConfig (CVE-2019-14540)</li> <li> jackson-databind: polymorphic typing issue related to com.zaxxer.hikari.HikariDataSource (CVE-2019-16335)</li> <li> jackson-databind: polymorphic typing issue when enabling default typing for an externally exposed JSON endpoint and having apache-log4j-extra in the classpath leads to code execution (CVE-2019-17531)</li> <li> jackson-databind: Serialization gadgets in classes of the commons-configuration package (CVE-2019-14892)</li> <li> jackson-databind: Serialization gadgets in classes of the commons-dbcp package (CVE-2019-16942)</li> <li> jackson-databind: Serialization gadgets in classes of the ehcache package (CVE-2019-17267)</li> <li> jackson-databind: Serialization gadgets in classes of the p6spy package (CVE-2019-16943)</li> <li> jackson-databind: Serialization gadgets in classes of the xalan package (CVE-2019-14893)</li> <li> mina-core: Retaining an open socket in closenotify SSL-TLS leading to Information disclosure (CVE-2019-0231)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model &amp; Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. <br>This release of Red Hat Decision Manager 7.5.0 serves as an update to Red Hat Decision Manager 7.4.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> jackson-databind: default typing mishandling leading to remote code execution (CVE-2019-14379)</li> <li> jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384)</li> <li> jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message (CVE-2019-12814)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )
SSRF

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model &amp; Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. <br>This release of Red Hat Decision Manager 7.4.0 serves as an update to Red Hat Decision Manager 7.3.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis (CVE-2018-11307)</li> <li> jackson-databind: improper polymorphic deserialization of types from Jodd-db library (CVE-2018-12022)</li> <li> jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver (CVE-2018-12023)</li> <li> jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718)</li> <li> jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719)</li> <li> jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360)</li> <li> jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361)</li> <li> jackson-databind: improper polymorphic deserialization in jboss-common-core class (CVE-2018-19362)</li> <li> jackson-databind: exfiltration/XXE in some JDK classes (CVE-2018-14720)</li> <li> jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class (CVE-2018-14721)</li> <li> xstream: remote code execution due to insecure XML deserialization (CVE-2019-10173, regression of CVE-2013-7285)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.1.0 serves as an update to Red Hat Decision Manager 7.0.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): Resteasy: Yaml unmarshalling vulnerable to RCE (CVE-2016-9606) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Red Hat would like to thank Moritz Bechler (AgNO3 GmbH & Co. KG) for reporting CVE-2016-9606.

Remedy

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.<br>It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.<br>The References section of this erratum contains a download link (you must log in to download the update).
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203