Known vulnerabilities in Red Hat OpenShift on IBM Cloud
Vendor:
IBM Corporation
Software:
Red Hat OpenShift on IBM Cloud
Software CPE:
cpe:2.3:a:ibm_corporation:red_hat_openshift_on_ibm_cloud:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
8
Public exploits:
5
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU127864 - Improper control of a resource through its lifetime CVE-2026-31431 |
CWE-664 | High | 4.16.60_1614, 4.17.52_1583, 4.18.38_1587, 4.19.29_1577, 4.20.19_1546 | 25.04.2026 |
SB20260425182 SB2026043080 SB2026050204 and 123 more |
||
| #VU105988 - Permissions, Privileges, and Access Controls CVE-2025-24514 |
CWE-264 | Medium | 4.16.60_1614, 4.17.52_1583, 4.18.38_1587, 4.19.29_1577, 4.20.19_1546 | 24.03.2025 |
SB2025032478 SB2025060659 SB20250620101 and 1 more |
||
| #VU105715 - Out-of-bounds write CVE-2025-27363 |
CWE-787 | Critical | 4.12.74 1631, 4.13.56 1614, 4.14.49 1604, 4.15.48 1581, 4.16.38 1562, 4.17.23 1535 | 14.03.2025 |
SB2025031402 SB2025031502 SB2025031750 and 97 more |
||
| #VU96712 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-45310 |
CWE-362 | Low | 4.13.51 1593, 4.15.35 1561, 4.16.15 1539 | 03.09.2024 |
SB2024090315 SB2024091283 SB2024091416 and 18 more |
||
| #VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-6387 |
CWE-362 | High | - | 01.07.2024 |
SB2024070144 SB2024070145 SB2024070152 and 89 more |
||
| #VU85991 - Security Features CVE-2024-21626 |
CWE-254 | High | 4.11.58 1591, 4.12.49 1578, 4.13.32 1557, 4.14.11 1547 | 01.02.2024 |
SB2024020112 SB2024020113 SB2024020123 and 78 more |
||
| #VU68299 - Incorrect Permission Assignment for Critical Resource CVE-2022-0532 |
CWE-732 | Medium | 4.8.35 1550, 4.9.25 1532 | 13.10.2022 |
SB2022101333 SB2022101334 SB2022101335 and 4 more |
||
| #VU67554 - Server-Side Request Forgery (SSRF) CVE-2022-3172 |
CWE-918 | Medium | 4.10.56, 4.11.12, 4.12.2 | 21.09.2022 |
SB2022092138 SB2022102614 SB2023011939 and 23 more |