PatchSiren

Red Hat CVE debriefs · Page 21

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Red Hat CVE published 2022-05-25

CVE-2010-1428

CVE-2010-1428 is a Red Hat JBoss information disclosure vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. In the supplied KEV record, CISA marked the issue as known exploited, noted known ransomware campaign use, and set a remediation due date of 2022-06-15. Because this is a KEV-listed vulnerability, defenders should treat it as a high-priority patch and exposure review [truncated]

Known exploited Red Hat CVE published 2022-05-25

CVE-2010-0738

CVE-2010-0738 is a Red Hat JBoss authentication bypass vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The KEV entry marks the issue as known to be exploited and notes known ransomware campaign use. The defensive action provided in the supplied corpus is to apply updates per vendor instructions.

Known exploited Red Hat CVE published 2021-12-10

CVE-2017-12149

CVE-2017-12149 is a Red Hat JBoss Application Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. The KEV entry indicates known ransomware campaign use and directs defenders to apply updates per vendor instructions. Because it is in KEV, this issue should be treated as actively exploited and prioritized for remediation.

Known exploited Red Hat CVE published 2021-12-10

CVE-2010-1871

CVE-2010-1871 is identified in CISA’s Known Exploited Vulnerabilities catalog for Red Hat JBoss Seam 2 and is labeled as a remote code execution vulnerability. Because CISA added it to KEV, defenders should treat it as actively exploited or at least operationally significant and prioritize remediation using vendor guidance.