Total vulnerabilities in the database
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Software | From | Fixed in |
---|---|---|
redhat / jboss_enterprise_application_platform | 7.0.0 | 7.0.0.x |
redhat / jboss_enterprise_application_platform | 7.2.0 | 7.2.0.x |
redhat / jboss_data_grid | 7.0.0 | 7.0.0.x |
redhat / jboss_enterprise_application_platform | 6.4.21 | 6.4.21.x |
redhat / jboss_enterprise_application_platform | 7.3.0 | 7.3.0.x |