Vulnerabilities (CVE)

Filtered by vendor Hawt Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2589 2 Hawt, Redhat 2 Hawtio, Jboss Fuse 2019-10-09 6.0 MEDIUM 9.0 CRITICAL
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
CVE-2019-9827 1 Hawt 1 Hawtio 2019-07-10 7.5 HIGH 9.8 CRITICAL
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.
CVE-2014-0121 2 Hawt, Redhat 2 Hawtio, Jboss Fuse 2018-01-11 7.5 HIGH 9.8 CRITICAL
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.