Known vulnerabilities in Red Hat Single Sign-On

Software CPE: cpe:2.3:a:red_hat:red_hat_single_sign-on:*:*:*:*:*:*:*:*
Total vulnerabilities: 255
Public exploits: 19
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat Single Sign-On Red Hat Single Sign-On is affected by 255 known vulnerabilities: 2 critical, 31 high, 147 medium, 75 low Critical High Medium Low

Vulnerabilities (255)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112106 - Memory corruption
CVE-2025-52999
CWE-119 Medium
No
No
7.6.12 02.07.2025 SB2025070257
SB2025070261
SB2025070262
and 43 more
#VU105956 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-10234
CWE-79 Low
No
No
7.6.12 24.03.2025 SB2025032404
SB2025032458
SB2025072352
and 3 more
#VU97622 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-8883
CWE-601 Low
No
No
7.6.11 20.09.2024 SB2024092009
SB2024092069
SB2024092070
and 12 more
#VU97621 - Improper Verification of Cryptographic Signature
CVE-2024-8698
CWE-347 Medium
Available
No
7.6.11 20.09.2024 SB2024092009
SB2024092069
SB2024092070
and 11 more
#VU97468 - Improper Restriction of Excessive Authentication Attempts
CVE-2024-4629
CWE-307 Medium
No
No
7.6.10 18.09.2024 SB2024091823
SB2024092059
SB2024092060
and 5 more
#VU97432 - Session Fixation
CVE-2024-7341
CWE-384 Medium
No
No
7.6.10 17.09.2024 SB2024091740
SB2024092059
SB2024092060
and 9 more
#VU95339 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-6345
CWE-94 High
No
No
7.6.10 05.08.2024 SB2024080590
SB2024080593
SB2024080594
and 160 more
#VU94711 - Resource exhaustion
CVE-2024-1975
CWE-400 Medium
No
No
7.6.10 24.07.2024 SB2024072415
SB2024072417
SB2024072418
and 72 more
#VU94710 - Resource Management Errors
CVE-2024-1737
CWE-399 Medium
No
No
7.6.10 24.07.2024 SB2024072415
SB2024072417
SB2024072418
and 73 more
#VU93519 - Out-of-bounds read
CVE-2024-37371
CWE-125 Medium
No
No
7.6.10 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 114 more
#VU93518 - Improper input validation
CVE-2024-37370
CWE-20 Medium
No
No
7.6.10 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 96 more
#VU93095 - Exposure of sensitive information to an unauthorized actor
CVE-2024-5967
CWE-200 Low
No
No
7.6.10 24.06.2024 SB2024062410
SB2024092059
SB2024092060
and 5 more
#VU93088 - Exposure of sensitive information to an unauthorized actor
CVE-2024-4540
CWE-200 Low
No
No
7.6.9 24.06.2024 SB2024062409
SB2024092061
SB2024092074
and 8 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
7.6.10 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
7.6.10 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU87185 - UNIX Symbolic Link (Symlink) Following
CVE-2023-6597
CWE-61 Low
No
No
7.6.9 07.03.2024 SB2024030718
SB2024030726
SB2024030727
and 88 more
#VU85658 - Insufficient Verification of Data Authenticity
CVE-2023-7008
CWE-345 Medium
No
No
7.6.9 22.01.2024 SB2024012238
SB2024012239
SB2024012240
and 38 more
#VU84540 - Unchecked Return Value
CVE-2023-6918
CWE-252 Low
No
No
7.6.9 19.12.2023 SB2023121906
SB2023121910
SB2023121911
and 63 more
#VU84538 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-6004
CWE-78 Medium
No
No
7.6.9 19.12.2023 SB2023121905
SB2023121906
SB2023121910
and 58 more
#VU81432 - Out-of-bounds read
CVE-2023-43785
CWE-125 Low
No
No
7.6.9 03.10.2023 SB2023100341
SB2023100347
SB2023100423
and 37 more


Showing elements 1 - 20 out of 255