RHSA-2024:5856

Advisory lineage Upstream: 21 Downstream: 0
Published: 29 Sept 2024, 18:52
Last modified:29 May 2026, 10:04

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
3.0 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Sept 2024, 18:52
Published
Vulnerability first disclosed
29 May 2026, 10:04
Last Modified
Vulnerability information updated

Description

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.7 on RHEL 7 security update

CVSS Metrics

  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • redhateap7-apache-commons-beanutils

    < 0:1.9.4-1.redhat_00002.1.ep7.el7

  • redhateap7-infinispan

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-infinispan-cachestore-jdbc

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-infinispan-cachestore-remote

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-infinispan-client-hotrod

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-infinispan-commons

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-infinispan-core

    < 0:8.2.11-1.SP2_redhat_00001.1.ep7.el7

  • redhateap7-jackson-databind

    < 0:2.8.11.5-1.redhat_00001.1.ep7.el7

  • redhateap7-log4j-jboss-logmanager

    < 0:1.2.2-1.Final_redhat_00002.1.ep7.el7

  • redhateap7-netty

    < 0:4.1.45-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-netty-all

    < 0:4.1.45-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-undertow

    < 0:1.4.18-12.SP12_redhat_00001.1.ep7.el7

  • redhateap7-wildfly

    < 0:7.1.7-2.GA_redhat_00002.1.ep7.el7

  • redhateap7-wildfly-elytron

    < 0:1.1.13-1.Final_redhat_00001.1.ep7.el7

  • redhateap7-wildfly-modules

    < 0:7.1.7-2.GA_redhat_00002.1.ep7.el7

References (110)