Known vulnerabilities in pki-servlet-engine (Red Hat package)
Vendor:
Red Hat Inc.
Software:
pki-servlet-engine (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:pki-servlet-engine_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
4
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117681 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-55752 |
CWE-22 | High | 9.0.43-4.el9_0.2, 9.0.50-1.el9_2.3 | 27.10.2025 |
SB2025102748 SB20251031122 SB20251031123 and 43 more |
||
| #VU107995 - Improper input validation CVE-2025-31651 |
CWE-20 | Medium | 9.0.43-4.el9_0.2, 9.0.50-1.el9_2.3 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 46 more |
||
| #VU97652 - Resource exhaustion CVE-2024-38286 |
CWE-400 | Medium | 9.0.43-4.el9_0.1, 9.0.50-1.el9_2.1 | 23.09.2024 |
SB2024092355 SB2024100267 SB2024102808 and 26 more |
||
| #VU57389 - Resource exhaustion CVE-2021-42340 |
CWE-400 | Medium | 9.0.50-1.el9 | 15.10.2021 |
SB2021101507 SB2021110507 SB2021111711 and 28 more |