Skip to content
COOEY

FAIL › dossier

Red Hat

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 50%

PROFILE
Categorysoftware companyWhat they doRed Hat is a leading provider of open-source software solutions, including operating systems, middleware, and storage software.
SECURITY POSTURE

Red Hat has faced multiple security vulnerabilities, indicating potential weaknesses in their products.

Notable failures
  • CVE-2010-0738: Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication.
  • CVE-2017-12149: Red Hat JBoss Application Server allowed remote code execution linked to ransomware.
  • CVE-2018-14667: Red Hat JBoss RichFaces Framework contained an expression language injection vulnerability.
  • CVE-2010-1428: Incomplete block in JBoss Web Console allowed unauthenticated access to sensitive information.
  • CVE-2010-1871: JBoss Seam 2 allowed remote code execution.
  • CVE-2021-3560: Red Hat Polkit contained an incorrect authorization vulnerability.
  • CVE-2021-4034: Red Hat polkit pkexec utility contained an out-of-bounds read and write vulnerability.
Patterns: Repeated unpatched critical vulnerabilities.; Linked to ransomware activity.; Remote code execution vulnerabilities.
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2022-05-25 CVE-2010-0738 critical Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods.
2026-08-26 CVE-2015-3246 high A race condition in Red Hat's libuser allowed authenticated local users to corrupt /etc/passwd, causing denial of service or privilege escalation.
2021-12-10 CVE-2010-1871 high JBoss Seam 2 in Red Hat Linux allows remote code execution when the Java Security Manager is misconfigured, and the flaw is actively exploited in the wild.
2023-09-28 CVE-2018-14667 high Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
2023-05-12 CVE-2021-3560 high Red Hat Polkit Incorrect Authorization Vulnerability
2021-12-10 CVE-2017-12149 critical A vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity.
2026-08-26 CVE-2015-5287 high A privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool allowed local users to escalate privileges via a symlink attack on a predictable file.
2022-05-25 CVE-2010-1428 critical An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.
2022-06-27 CVE-2021-4034 high A Red Hat Polkit vulnerability allowed privilege escalation, actively exploited in the wild, impacting systems relying on it for authorization.
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
Red Hat OpenShift Service on AWS (ROSA)In ProcessHigh
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:45:52.011276+00:00