Known vulnerabilities in rh-sso7-javapackages-tools (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-sso7-javapackages-tools_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 8
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-sso7-javapackages-tools (Red Hat package) rh-sso7-javapackages-tools (Red Hat package) is affected by 8 known vulnerabilities: 1 critical, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68867 - Improper input validation
CVE-2022-0839
CWE-20 Low
No
No
3.4.1-5.15.3.jbcs.el7, 3.4.1-5.15.6.el8sso 01.11.2022 SB2022110114
SB2022121929
SB2022121930
and 3 more
#VU67936 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0225
CWE-79 Low
No
No
6.0.0-7.el9sso 05.10.2022 SB2022100527
SB2022100530
SB2022100531
and 6 more
#VU67935 - Permissions, Privileges, and Access Controls
CVE-2022-2668
CWE-264 Low
No
No
6.0.0-7.el9sso 05.10.2022 SB2022100527
SB2022100530
SB2022100531
and 5 more
#VU64037 - Incorrect Authorization
CVE-2022-0866
CWE-863 Low
No
No
6.0.0-7.el9sso 07.06.2022 SB2022060718
SB2022060838
SB2022100530
and 6 more
#VU63159 - Allocation of Resources Without Limits or Throttling
CVE-2022-0084
CWE-770 Low
No
No
6.0.0-7.el9sso 13.05.2022 SB2022051310
SB2022051311
SB2022060838
and 12 more
#VU61937 - Deserialization of Untrusted Data
CVE-2021-42392
CWE-502 Critical
Available
No
6.0.0-7.el9sso 06.04.2022 SB2022040617
SB2022040619
SB2022042257
and 10 more
#VU61810 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-43797
CWE-444 Medium
No
No
6.0.0-7.el9sso 02.04.2022 SB2021120923
SB2022040202
SB2022042223
and 49 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
6.0.0-7.el9sso 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more