PROFILE
Categorysoftware companyWhat they doRed Hat is a leading provider of open-source software solutions, including operating systems, middleware, and storage software.
SECURITY POSTURE
Red Hat has faced multiple security vulnerabilities, indicating potential weaknesses in their products.
Notable failures
- CVE-2010-0738: Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication.
- CVE-2017-12149: Red Hat JBoss Application Server allowed remote code execution linked to ransomware.
- CVE-2018-14667: Red Hat JBoss RichFaces Framework contained an expression language injection vulnerability.
- CVE-2010-1428: Incomplete block in JBoss Web Console allowed unauthenticated access to sensitive information.
- CVE-2010-1871: JBoss Seam 2 allowed remote code execution.
- CVE-2021-3560: Red Hat Polkit contained an incorrect authorization vulnerability.
- CVE-2021-4034: Red Hat polkit pkexec utility contained an out-of-bounds read and write vulnerability.
Patterns: Repeated unpatched critical vulnerabilities.; Linked to ransomware activity.; Remote code execution vulnerabilities.
FAILURE HISTORY · 9
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-25 | CVE-2010-0738 | critical | Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods. |
| 2026-08-26 | CVE-2015-3246 | high | A race condition in Red Hat's libuser allowed authenticated local users to corrupt /etc/passwd, causing denial of service or privilege escalation. |
| 2021-12-10 | CVE-2010-1871 | high | JBoss Seam 2 in Red Hat Linux allows remote code execution when the Java Security Manager is misconfigured, and the flaw is actively exploited in the wild. |
| 2023-09-28 | CVE-2018-14667 | high | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability |
| 2023-05-12 | CVE-2021-3560 | high | Red Hat Polkit Incorrect Authorization Vulnerability |
| 2021-12-10 | CVE-2017-12149 | critical | A vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity. |
| 2026-08-26 | CVE-2015-5287 | high | A privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool allowed local users to escalate privileges via a symlink attack on a predictable file. |
| 2022-05-25 | CVE-2010-1428 | critical | An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST. |
| 2022-06-27 | CVE-2021-4034 | high | A Red Hat Polkit vulnerability allowed privilege escalation, actively exploited in the wild, impacting systems relying on it for authorization. |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Red Hat OpenShift Service on AWS (ROSA) | In Process | High |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:45:52.011276+00:00