Skip to main content

Red Hat security briefs

4 published alerts for Red Hat products and services.

Actively exploited (KEV)Ransomware

CVE-2021-4034

Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

Red Hat Polkit is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-4034). The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. CISA remediation due date: 2022-07-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-1428

Red Hat JBoss Information Disclosure Vulnerability

Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-1428). Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2010-0738

Red Hat JBoss Authentication Bypass Vulnerability

Red Hat JBoss is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2010-0738). The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-12149

Red Hat JBoss Application Server Remote Code Execution Vulnerability

Red Hat JBoss Application Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-12149). The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. CISA remediation due date: 2022-06-10. If you need help checking exposure, call (864) 335-9223.