https://bugzilla.redhat.com/show_bug.cgi?id=2108554
https://access.redhat.com/security/updates/classification/#important
http://www.nessus.org/u?919aa761
https://bugzilla.redhat.com/show_bug.cgi?id=2278615
https://issues.redhat.com/browse/JBEAP-27002
https://issues.redhat.com/browse/JBEAP-27194
https://bugzilla.redhat.com/show_bug.cgi?id=2311641
https://bugzilla.redhat.com/show_bug.cgi?id=2312511
https://access.redhat.com/errata/RHSA-2024:8823
https://bugzilla.redhat.com/show_bug.cgi?id=2298829
https://bugzilla.redhat.com/show_bug.cgi?id=2309764
https://issues.redhat.com/browse/JBEAP-24945
https://issues.redhat.com/browse/JBEAP-25035
https://issues.redhat.com/browse/JBEAP-27247
https://issues.redhat.com/browse/JBEAP-27276
https://issues.redhat.com/browse/JBEAP-27293
https://issues.redhat.com/browse/JBEAP-27392
https://issues.redhat.com/browse/JBEAP-27543
https://issues.redhat.com/browse/JBEAP-27585
https://issues.redhat.com/browse/JBEAP-27643
https://issues.redhat.com/browse/JBEAP-27659
https://issues.redhat.com/browse/JBEAP-27688
https://issues.redhat.com/browse/JBEAP-27694
https://issues.redhat.com/browse/JBEAP-27957
https://issues.redhat.com/browse/JBEAP-28057
https://issues.redhat.com/browse/JBEAP-28278
Severity: High
ID: 210339
File Name: redhat-RHSA-2024-8823.nasl
Version: 1.1
Type: local
Agent: unix
Family: Red Hat Local Security Checks
Published: 11/5/2024
Updated: 11/5/2024
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus
Risk Factor: High
Score: 8.5
Vendor Severity: Important
Risk Factor: High
Base Score: 7.8
Temporal Score: 6.1
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N
CVSS Score Source: CVE-2022-34169
Risk Factor: High
Base Score: 7.7
Temporal Score: 6.9
Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
CVSS Score Source: CVE-2024-8698
CPE: cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:eap8-log4j, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk11, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-codec, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-io, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-validator, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-validator-cdi, p-cpe:/a:redhat:enterprise_linux:eap8-insights-java-client, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-cert-helper, p-cpe:/a:redhat:enterprise_linux:eap8-jgroups, p-cpe:/a:redhat:enterprise_linux:eap8-narayana, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbosstxbridge, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbossxts, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-idlj, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-integration, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-api, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-bridge, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-integration, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-util, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-snakeyaml, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-native, p-cpe:/a:redhat:enterprise_linux:eap8-aesh-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-aesh-readline, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-collections, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-lang, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-native, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-native-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap8-asyncutil, p-cpe:/a:redhat:enterprise_linux:eap8-aws-java-sdk, p-cpe:/a:redhat:enterprise_linux:eap8-aws-java-sdk-core, p-cpe:/a:redhat:enterprise_linux:eap8-aws-java-sdk-kms, p-cpe:/a:redhat:enterprise_linux:eap8-aws-java-sdk-s3, p-cpe:/a:redhat:enterprise_linux:eap8-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap8-fastinfoset, p-cpe:/a:redhat:enterprise_linux:eap8-hppc, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-servlet-jsp-jstl, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-servlet-jsp-jstl-api, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-jctools, p-cpe:/a:redhat:enterprise_linux:eap8-jctools-core, p-cpe:/a:redhat:enterprise_linux:eap8-jmespath-java, p-cpe:/a:redhat:enterprise_linux:eap8-nimbus-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap8-objectweb-asm, p-cpe:/a:redhat:enterprise_linux:eap8-objectweb-asm-util, p-cpe:/a:redhat:enterprise_linux:eap8-pem-keystore, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-spring, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-tracing-api, p-cpe:/a:redhat:enterprise_linux:eap8-saaj-impl, p-cpe:/a:redhat:enterprise_linux:eap8-shibboleth-java-support
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 11/4/2024
Vulnerability Publication Date: 7/19/2022
CVE: CVE-2022-34169, CVE-2023-52428, CVE-2024-4029, CVE-2024-41172, CVE-2024-8698, CVE-2024-8883