RHSA-2024:10208

Advisory lineage Upstream: 12 Downstream: 0
Published: 26 Nov 2024, 07:31
Last modified:28 May 2026, 10:03

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Nov 2024, 07:31
Published
Vulnerability first disclosed
28 May 2026, 10:03
Last Modified
Vulnerability information updated

Description

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.8 on RHEL 7 security update

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • redhateap7-apache-cxf

    < 0:3.1.16-3.SP1_redhat_00001.1.ep7.el7

  • redhateap7-apache-cxf-rt

    < 0:3.1.16-3.SP1_redhat_00001.1.ep7.el7

  • redhateap7-apache-cxf-services

    < 0:3.1.16-3.SP1_redhat_00001.1.ep7.el7

  • redhateap7-apache-cxf-tools

    < 0:3.1.16-3.SP1_redhat_00001.1.ep7.el7

  • redhateap7-avro

    < 0:1.7.6-2.redhat_00003.1.ep7.el7

  • redhateap7-bouncycastle

    < 0:1.68.0-1.redhat_00005.1.ep7.el7

  • redhateap7-bouncycastle-mail

    < 0:1.68.0-1.redhat_00005.1.ep7.el7

  • redhateap7-bouncycastle-pkix

    < 0:1.68.0-1.redhat_00005.1.ep7.el7

  • redhateap7-bouncycastle-prov

    < 0:1.68.0-1.redhat_00005.1.ep7.el7

  • redhateap7-h2database

    < 0:1.4.197-2.redhat_00005.1.ep7.el7

  • redhateap7-jackson-databind

    < 0:2.8.11.6-1.SP1_redhat_00001.1.ep7.el7

  • redhateap7-jboss-marshalling

    < 0:2.0.15-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-jboss-marshalling-river

    < 0:2.0.15-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-jboss-xnio-base

    < 0:3.5.10-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-wildfly

    < 0:7.1.8-2.GA_redhat_00002.1.ep7.el7

  • redhateap7-wildfly-modules

    < 0:7.1.8-2.GA_redhat_00002.1.ep7.el7

  • redhateap7-xalan-j2

    < 0:2.7.1-26.redhat_00015.1.ep7.el7

References (63)