Known vulnerabilities in ipa (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:ipa_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 24
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ipa (Red Hat package) ipa (Red Hat package) is affected by 24 known vulnerabilities: 2 high, 8 medium, 14 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116216 - Insufficient Granularity of Access Control
CVE-2025-7493
CWE-1220 Medium
No
No
4.6.8-5.el7_9.23, 4.9.8-11.el9_0.5, 4.10.1-12.el9_2.6, 4.11.0-15.el9_4.7, 4.12.2-14.el9_6.5, 4.12.2-15.el10_0.4 01.10.2025 SB2025100120
SB2025100123
SB2025100124
and 14 more
#VU112054 - Improper input validation
CVE-2025-4404
CWE-20 Medium
Available
No
4.6.8-5.el7_9.18, 4.9.8-11.el9_0.4, 4.10.1-12.el9_2.4, 4.11.0-15.el9_4.5, 4.12.2-14.el9_6.1, 4.12.2-15.el10_0.1 30.06.2025 SB2025063081
SB2025063085
SB2025063086
and 14 more
#VU103304 - Information Exposure Through Log Files
CVE-2024-11029
CWE-532 Low
No
No
4.12.2-1.el9_5.3 24.01.2025 SB2025012493
SB2025012494
SB2025012496
and 1 more
#VU92249 - Use of Password Hash With Insufficient Computational Effort
CVE-2024-3183
CWE-916 Low
Available
No
4.6.8-5.el7_9.17, 4.9.8-11.el9_0.3, 4.10.1-12.el9_2.2, 4.11.0-15.el9_4 19.06.2024 SB2024061917
SB2024061918
SB2024061919
and 11 more
#VU92247 - Improper Authorization
CVE-2024-2698
CWE-285 Medium
No
No
4.10.1-12.el9_2.2, 4.11.0-15.el9_4 19.06.2024 SB2024061917
SB2024061919
SB2024061920
and 5 more
#VU87167 - Improper input validation
CVE-2024-1481
CWE-20 Medium
No
No
4.11.0-9.el9_4 06.03.2024 SB2024030645
SB2024030665
SB2024030666
and 5 more
#VU85268 - Cross-Site Request Forgery (CSRF)
CVE-2023-5455
CWE-352 Medium
No
No
4.6.8-5.el7_9.16, 4.9.8-9.el9_0, 4.10.1-10.el9_2, 4.10.2-5.el9_3 10.01.2024 SB2024011032
SB2024011039
SB2024011040
and 17 more
#VU58095 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-25719
CWE-362 Low
No
No
4.6.8-5.el7_9.10 10.11.2021 SB2021111008
SB2021111201
SB2021121644
and 17 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
4.6.5-11.el7_7.5, 4.6.8-5.el7_9.4 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU47198 - Resource exhaustion
CVE-2020-1722
CWE-400 Medium
No
No
4.6.8-5.el7 27.04.2020 SB2020042729
SB2020093090
SB2020110508
#VU27052 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11022
CWE-79 Low
Available
No
4.6.8-5.el7 21.04.2020 SB2020042126
SB2020052033
SB2020052103
and 181 more
#VU26102 - Information Exposure Through Log Files
CVE-2019-10195
CWE-532 Low
No
No
4.6.5-11.el7_7.4 17.03.2020 SB2019112719
SB2019121718
SB2020040168
and 4 more
#VU21707 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-10735
CWE-79 Low
No
No
4.6.8-5.el7 10.10.2019 SB2019010911
SB2019101009
SB2020093090
and 21 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
4.6.8-5.el7 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more
#VU17694 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8331
CWE-79 Low
No
No
4.6.8-5.el7 14.02.2019 SB2019021412
SB2019031501
SB2019101009
and 28 more
#VU16956 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20676
CWE-79 Low
No
No
4.6.8-5.el7 13.01.2019 SB2018121404
SB2019101009
SB2020093090
and 18 more
#VU16542 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-20677
CWE-79 Low
No
No
4.6.8-5.el7 14.12.2018 SB2018121404
SB2019101009
SB2020093090
and 18 more
#VU14150 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-9251
CWE-79 Low
No
No
4.6.8-5.el7 31.07.2018 SB2018080106
SB2019011705
SB2019100301
and 63 more
#VU13902 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14042
CWE-79 Low
No
No
4.6.8-5.el7 18.07.2018 SB2018071803
SB2020093090
SB2020110508
and 22 more
#VU13901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-14040
CWE-79 Low
No
No
4.6.8-5.el7 17.07.2018 SB2018071803
SB2019031501
SB2020093090
and 24 more


Showing elements 1 - 20 out of 24