Language:
https://issues.redhat.com/browse/JBEAP-27895
https://issues.redhat.com/browse/JBEAP-27941
https://issues.redhat.com/browse/JBEAP-28024
https://issues.redhat.com/browse/JBEAP-28026
https://issues.redhat.com/browse/JBEAP-28037
https://issues.redhat.com/browse/JBEAP-28046
https://issues.redhat.com/browse/JBEAP-28139
https://issues.redhat.com/browse/JBEAP-28140
https://issues.redhat.com/browse/JBEAP-28211
https://issues.redhat.com/browse/JBEAP-28248
https://issues.redhat.com/browse/JBEAP-28265
https://issues.redhat.com/browse/JBEAP-28288
https://issues.redhat.com/browse/JBEAP-28325
https://issues.redhat.com/browse/JBEAP-28336
https://issues.redhat.com/browse/JBEAP-28337
https://issues.redhat.com/browse/JBEAP-28338
https://issues.redhat.com/browse/JBEAP-28378
https://issues.redhat.com/browse/JBEAP-28386
https://issues.redhat.com/browse/JBEAP-28541
http://www.nessus.org/u?5afd2289
https://access.redhat.com/errata/RHSA-2024:11560
https://access.redhat.com/security/updates/classification/#important
http://www.nessus.org/u?451267bf
https://bugzilla.redhat.com/show_bug.cgi?id=2272325
https://bugzilla.redhat.com/show_bug.cgi?id=2323697
https://issues.redhat.com/browse/JBEAP-27429
https://issues.redhat.com/browse/JBEAP-27430
https://issues.redhat.com/browse/JBEAP-27443
https://issues.redhat.com/browse/JBEAP-27451
https://issues.redhat.com/browse/JBEAP-27452
https://issues.redhat.com/browse/JBEAP-27646
https://issues.redhat.com/browse/JBEAP-27662
Severity: High
ID: 213258
File Name: redhat-RHSA-2024-11560.nasl
Version: 1.1
Type: local
Agent: unix
Family: Red Hat Local Security Checks
Published: 12/19/2024
Updated: 12/19/2024
Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus
Risk Factor: Medium
Score: 6.0
Vendor Severity: Important
Risk Factor: Medium
Base Score: 6.2
Temporal Score: 4.9
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N
CVSS Score Source: CVE-2024-51127
Risk Factor: High
Base Score: 7.1
Temporal Score: 6.4
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
CPE: p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-core, p-cpe:/a:redhat:enterprise_linux:eap8-hornetq-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-ee, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-client-webservices, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-parsson, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-crypto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-ecj, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-client-resteasy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-undertow-jastow, p-cpe:/a:redhat:enterprise_linux:eap8-apache-commons-lang, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-atinject, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-authorization, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jackson2-provider, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-integration, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-rxjava2, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-client-api, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk11, p-cpe:/a:redhat:enterprise_linux:eap8-hal-console, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-jansi, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-jctools-core, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-util, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-client, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-core-spi, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-json-p-provider, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-cdi, p-cpe:/a:redhat:enterprise_linux:eap8-azure-storage, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-atom-provider, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-json-binding-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-marshalling, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-validator-provider, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-hornetq-commons, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-weld-api, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jts-idlj, p-cpe:/a:redhat:enterprise_linux:eap8-jctools, p-cpe:/a:redhat:enterprise_linux:eap8-undertow, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-marshalling-river, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-authentication, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbossxts, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy, p-cpe:/a:redhat:enterprise_linux:eap8-angus-activation, p-cpe:/a:redhat:enterprise_linux:eap8-yasson, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-jbosstxbridge, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jsapi, p-cpe:/a:redhat:enterprise_linux:eap8-vdx, p-cpe:/a:redhat:enterprise_linux:eap8-jsonb-spec, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-narayana, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-bridge, p-cpe:/a:redhat:enterprise_linux:eap8-vdx-core, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-multipart-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-security, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-ejb-client, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-activation, p-cpe:/a:redhat:enterprise_linux:eap8-expressly, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-commons-logging-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-integration, p-cpe:/a:redhat:enterprise_linux:eap8-javaee-security-soteria-enterprise, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-resteasy-jaxb-provider, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-vdx-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-weld-api-weld-spi, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-javaee-security-soteria, p-cpe:/a:redhat:enterprise_linux:eap8-narayana-restat-api, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-hornetq, p-cpe:/a:redhat:enterprise_linux:eap8-hornetq-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-weld-api-weld-api
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 12/19/2024
Vulnerability Publication Date: 11/4/2024
CVE: CVE-2024-4109, CVE-2024-51127
RHSA: 2024:11560