Vulnerability Database
Blog
FAQ
Docs
RHSA-2024:10208
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2024:10208
Import Source
https://security.access.redhat.com/data/osv/RHSA-2024:10208.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2024:10208
Related
CVE-2020-28052
CVE-2020-7238
CVE-2022-23221
CVE-2022-34169
CVE-2022-41853
CVE-2022-46364
CVE-2023-26464
CVE-2023-3171
CVE-2023-39410
CVE-2023-5685
CVE-2024-28752
CVE-2024-47561
Published
2024-11-26T07:31:51Z
Modified
2024-12-12T10:02:07Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.8 on RHEL 7 security update
Details
References
https://access.redhat.com/errata/RHSA-2024:10208
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
https://bugzilla.redhat.com/show_bug.cgi?id=1796225
https://bugzilla.redhat.com/show_bug.cgi?id=1912881
https://bugzilla.redhat.com/show_bug.cgi?id=2044596
https://bugzilla.redhat.com/show_bug.cgi?id=2108554
https://bugzilla.redhat.com/show_bug.cgi?id=2136141
https://bugzilla.redhat.com/show_bug.cgi?id=2155682
https://bugzilla.redhat.com/show_bug.cgi?id=2182864
https://bugzilla.redhat.com/show_bug.cgi?id=2213639
https://bugzilla.redhat.com/show_bug.cgi?id=2241822
https://bugzilla.redhat.com/show_bug.cgi?id=2242521
https://bugzilla.redhat.com/show_bug.cgi?id=2270732
https://bugzilla.redhat.com/show_bug.cgi?id=2316116
https://issues.redhat.com/browse/JBEAP-27708
https://issues.redhat.com/browse/JBEAP-28086
https://issues.redhat.com/browse/JBEAP-28130
https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10208.json
https://access.redhat.com/security/cve/CVE-2020-7238
https://www.cve.org/CVERecord?id=CVE-2020-7238
https://nvd.nist.gov/vuln/detail/CVE-2020-7238
https://netty.io/news/2019/12/18/4-1-44-Final.html
https://access.redhat.com/security/cve/CVE-2020-28052
https://www.cve.org/CVERecord?id=CVE-2020-28052
https://nvd.nist.gov/vuln/detail/CVE-2020-28052
https://access.redhat.com/security/cve/CVE-2022-23221
https://www.cve.org/CVERecord?id=CVE-2022-23221
https://nvd.nist.gov/vuln/detail/CVE-2022-23221
https://github.com/advisories/GHSA-45hx-wfhj-473x
https://access.redhat.com/security/cve/CVE-2022-34169
https://www.cve.org/CVERecord?id=CVE-2022-34169
https://nvd.nist.gov/vuln/detail/CVE-2022-34169
https://access.redhat.com/security/cve/CVE-2022-41853
https://www.cve.org/CVERecord?id=CVE-2022-41853
https://nvd.nist.gov/vuln/detail/CVE-2022-41853
http://hsqldb.org/doc/2.0/guide/sqlroutines-chapt.html#src_jrt_access_control
https://github.com/advisories/GHSA-77xx-rxvh-q682
https://access.redhat.com/security/cve/CVE-2022-46364
https://www.cve.org/CVERecord?id=CVE-2022-46364
https://nvd.nist.gov/vuln/detail/CVE-2022-46364
https://cxf.apache.org/security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944472739&api=v2
https://access.redhat.com/security/cve/CVE-2023-3171
https://www.cve.org/CVERecord?id=CVE-2023-3171
https://nvd.nist.gov/vuln/detail/CVE-2023-3171
https://access.redhat.com/security/cve/CVE-2023-5685
https://www.cve.org/CVERecord?id=CVE-2023-5685
https://nvd.nist.gov/vuln/detail/CVE-2023-5685
https://access.redhat.com/security/cve/CVE-2023-26464
https://www.cve.org/CVERecord?id=CVE-2023-26464
https://nvd.nist.gov/vuln/detail/CVE-2023-26464
https://www.ibm.com/support/pages/security-bulletin-vulnerability-log4j-1216jar-affect-ibm-operations-analytics-log-analysis-cve-2023-26464
https://access.redhat.com/security/cve/CVE-2023-39410
https://www.cve.org/CVERecord?id=CVE-2023-39410
https://nvd.nist.gov/vuln/detail/CVE-2023-39410
https://issues.apache.org/jira/browse/AVRO-3819
https://access.redhat.com/security/cve/CVE-2024-28752
https://www.cve.org/CVERecord?id=CVE-2024-28752
https://nvd.nist.gov/vuln/detail/CVE-2024-28752
https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt
https://github.com/advisories/GHSA-qmgx-j96g-4428
https://access.redhat.com/security/cve/CVE-2024-47561
https://www.cve.org/CVERecord?id=CVE-2024-47561
https://nvd.nist.gov/vuln/detail/CVE-2024-47561
Affected packages
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf
Package
Name
eap7-apache-cxf
Purl
pkg:rpm/redhat/eap7-apache-cxf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-rt
Package
Name
eap7-apache-cxf-rt
Purl
pkg:rpm/redhat/eap7-apache-cxf-rt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-services
Package
Name
eap7-apache-cxf-services
Purl
pkg:rpm/redhat/eap7-apache-cxf-services
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-tools
Package
Name
eap7-apache-cxf-tools
Purl
pkg:rpm/redhat/eap7-apache-cxf-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-avro
Package
Name
eap7-avro
Purl
pkg:rpm/redhat/eap7-avro
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.6-2.redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-bouncycastle
Package
Name
eap7-bouncycastle
Purl
pkg:rpm/redhat/eap7-bouncycastle
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.68.0-1.redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-bouncycastle-mail
Package
Name
eap7-bouncycastle-mail
Purl
pkg:rpm/redhat/eap7-bouncycastle-mail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.68.0-1.redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-bouncycastle-pkix
Package
Name
eap7-bouncycastle-pkix
Purl
pkg:rpm/redhat/eap7-bouncycastle-pkix
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.68.0-1.redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-bouncycastle-prov
Package
Name
eap7-bouncycastle-prov
Purl
pkg:rpm/redhat/eap7-bouncycastle-prov
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.68.0-1.redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-h2database
Package
Name
eap7-h2database
Purl
pkg:rpm/redhat/eap7-h2database
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.197-2.redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jackson-databind
Package
Name
eap7-jackson-databind
Purl
pkg:rpm/redhat/eap7-jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jboss-marshalling
Package
Name
eap7-jboss-marshalling
Purl
pkg:rpm/redhat/eap7-jboss-marshalling
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.15-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jboss-marshalling-river
Package
Name
eap7-jboss-marshalling-river
Purl
pkg:rpm/redhat/eap7-jboss-marshalling-river
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.15-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jboss-xnio-base
Package
Name
eap7-jboss-xnio-base
Purl
pkg:rpm/redhat/eap7-jboss-xnio-base
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.10-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly
Package
Name
eap7-wildfly
Purl
pkg:rpm/redhat/eap7-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-modules
Package
Name
eap7-wildfly-modules
Purl
pkg:rpm/redhat/eap7-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-xalan-j2
Package
Name
eap7-xalan-j2
Purl
pkg:rpm/redhat/eap7-xalan-j2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.7.1-26.redhat_00015.1.ep7.el7
RHSA-2024:10208 - OSV