Known vulnerabilities in eap7-jackson-modules-java8 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:eap7-jackson-modules-java8_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 31
Public exploits: 9
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting eap7-jackson-modules-java8 (Red Hat package) eap7-jackson-modules-java8 (Red Hat package) is affected by 31 known vulnerabilities: 2 critical, 6 high, 12 medium, 11 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114026 - Resource exhaustion
CVE-2025-55163
CWE-400 Medium
No
No
2.8.11-2.redhat_00004.1.ep7.el7, 2.10.4-3.redhat_00008.1.el7eap 13.08.2025 SB2025081378
SB2025081948
SB2025081949
and 71 more
#VU112106 - Memory corruption
CVE-2025-52999
CWE-119 Medium
No
No
2.8.11-2.redhat_00004.1.ep7.el7, 2.10.4-3.redhat_00008.1.el7eap 02.07.2025 SB2025070257
SB2025070261
SB2025070262
and 43 more
#VU96900 - Exposure of sensitive information to an unauthorized actor
CVE-2024-7885
CWE-200 Medium
No
No
2.10.4-3.redhat_00008.1.el7eap 05.09.2024 SB2024090598
SB2024090599
SB2024092018
and 16 more
#VU71713 - Observable discrepancy
CVE-2022-3143
CWE-203 Medium
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 31.01.2023 SB2023013123
SB2023013124
SB2023013125
and 3 more
#VU70443 - Exposure of sensitive information to an unauthorized actor
CVE-2022-46363
CWE-200 Low
No
No
2.10.4-2.redhat_00004.1.el7eap 20.12.2022 SB2022122009
SB2023011707
SB2023012719
and 22 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
2.10.4-2.redhat_00004.1.el7eap 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70118 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-41881
CWE-835 Medium
No
No
2.10.4-2.redhat_00004.1.el7eap 12.12.2022 SB2022121215
SB2023011210
SB2023011757
and 74 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
2.10.4-2.redhat_00004.1.el7eap 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
2.10.4-2.redhat_00004.1.el7eap 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU61937 - Deserialization of Untrusted Data
CVE-2021-42392
CWE-502 Critical
Available
No
2.10.4-2.redhat_00004.1.el7eap 06.04.2022 SB2022040617
SB2022040619
SB2022042257
and 10 more
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
2.10.4-2.redhat_00004.1.el7eap 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
2.10.4-2.redhat_00004.1.el7eap 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU51511 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-13936
CWE-94 High
No
No
2.10.4-2.redhat_00004.1.el7eap 16.03.2021 SB2021031618
SB2021072614
SB2022011911
and 45 more
#VU21707 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-10735
CWE-79 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 10.10.2019 SB2019010911
SB2019101009
SB2020093090
and 21 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more
#VU17694 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8331
CWE-79 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 14.02.2019 SB2019021412
SB2019031501
SB2019101009
and 28 more
#VU13903 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14041
CWE-79 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 18.07.2018 SB2018071803
SB2019031501
SB2023013124
and 8 more
#VU13902 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14042
CWE-79 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 18.07.2018 SB2018071803
SB2020093090
SB2020110508
and 22 more
#VU13901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14040
CWE-79 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 17.07.2018 SB2018071803
SB2019031501
SB2020093090
and 24 more
#VU11300 - Resource exhaustion
CVE-2017-18214
CWE-400 Low
No
No
2.12.7-1.redhat_00003.1.el7eap, 2.12.7-1.redhat_00003.1.el8eap, 2.12.7-1.redhat_00003.1.el9eap 28.03.2018 SB2017090813
SB2022022516
SB2022101031
and 8 more


Showing elements 1 - 20 out of 31