Red Hat security briefs
4 published alerts for Red Hat products and services.
Red Hat Polkit Out-of-Bounds Read and Write Vulnerability
Red Hat Polkit is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-4034). The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. CISA remediation due date: 2022-07-18. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Information Disclosure Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-1428). Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Authentication Bypass Vulnerability
Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0738). The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.