Show plain JSON{"affected_release": [{"advisory": "RHSA-2014:1320", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el5", "package": "jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5", "product_name": "JBEWP 5 for RHEL 5", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1320", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el5", "package": "jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5", "product_name": "JBEWP 5 for RHEL 5", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1833", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el5", "package": "apache-cxf-0:2.2.12-14.patch_09.ep5.el5", "product_name": "JBEWP 5 for RHEL 5", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1320", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el6", "package": "jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5", "product_name": "JBEWP 5 for RHEL 6", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1320", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el6", "package": "jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6", "product_name": "JBEWP 5 for RHEL 6", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1833", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5::el6", "package": "apache-cxf-0:2.2.12-14.patch_09.el6", "product_name": "JBEWP 5 for RHEL 6", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1166", "cpe": "cpe:/o:redhat:enterprise_linux:5", "package": "jakarta-commons-httpclient-1:3.0-7jpp.4.el5_10", "product_name": "Red Hat Enterprise Linux 5", "release_date": "2014-09-08T00:00:00Z"}, {"advisory": "RHSA-2014:1166", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "jakarta-commons-httpclient-1:3.1-0.9.el6_5", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2014-09-08T00:00:00Z"}, {"advisory": "RHSA-2014:1146", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "httpcomponents-client-0:4.2.5-5.el7_0", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2014-09-03T00:00:00Z"}, {"advisory": "RHSA-2014:1166", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "jakarta-commons-httpclient-1:3.1-16.el7_0", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2014-09-08T00:00:00Z"}, {"advisory": "RHSA-2016:1931", "cpe": "cpe:/a:redhat:jboss_amq:6.2", "product_name": "Red Hat JBoss A-MQ 6.2", "release_date": "2016-09-23T00:00:00Z"}, {"advisory": "RHSA-2015:1177", "cpe": "cpe:/a:redhat:jboss_amq:6.2.0", "product_name": "Red Hat JBoss A-MQ 6.2", "release_date": "2015-06-23T00:00:00Z"}, {"advisory": "RHSA-2014:1892", "cpe": "cpe:/a:redhat:jboss_bpms:6.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss BPMS 6.0", "release_date": "2014-11-24T00:00:00Z"}, {"advisory": "RHSA-2015:0234", "cpe": "cpe:/a:redhat:jboss_bpms:6.0", "package": "httpclient", "product_name": "Red Hat JBoss BPMS 6.0", "release_date": "2015-02-17T00:00:00Z"}, {"advisory": "RHSA-2015:0851", "cpe": "cpe:/a:redhat:jboss_bpms:6.0", "package": "cxf", "product_name": "Red Hat JBoss BPMS 6.0", "release_date": "2015-04-16T00:00:00Z"}, {"advisory": "RHSA-2015:0851", "cpe": "cpe:/a:redhat:jboss_bpms:6.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss BPMS 6.0", "release_date": "2015-04-16T00:00:00Z"}, {"advisory": "RHSA-2014:1891", "cpe": "cpe:/a:redhat:jboss_brms:6.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss BRMS 6.0", "release_date": "2014-11-24T00:00:00Z"}, {"advisory": "RHSA-2015:0235", "cpe": "cpe:/a:redhat:jboss_brms:6.0", "package": "httpclient", "product_name": "Red Hat JBoss BRMS 6.0", "release_date": "2015-02-17T00:00:00Z"}, {"advisory": "RHSA-2015:0850", "cpe": "cpe:/a:redhat:jboss_brms:6.0", "package": "cxf", "product_name": "Red Hat JBoss BRMS 6.0", "release_date": "2015-04-16T00:00:00Z"}, {"advisory": "RHSA-2015:0850", "cpe": "cpe:/a:redhat:jboss_brms:6.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss BRMS 6.0", "release_date": "2015-04-16T00:00:00Z"}, {"advisory": "RHSA-2015:0765", "cpe": "cpe:/a:redhat:jboss_data_virtualization:6.0", "package": "httpclient", "product_name": "Red Hat JBoss Data Virtualization 6.0", "release_date": "2015-03-31T00:00:00Z"}, {"advisory": "RHSA-2015:0675", "cpe": "cpe:/a:redhat:jboss_data_virtualization:6.1", "product_name": "Red Hat JBoss Data Virtualization 6.1", "release_date": "2015-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:1323", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0", "package": "httpclient", "product_name": "Red Hat JBoss Enterprise Application Platform 5.2", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1323", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Enterprise Application Platform 5.2", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1836", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0", "product_name": "Red Hat JBoss Enterprise Application Platform 5.2", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el4", "package": "jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el4", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 4", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el4", "package": "jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el4", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 4", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1834", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el4", "package": "apache-cxf-0:2.2.12-14.patch_09.ep5.el4", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 4", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el5", "package": "jakarta-commons-httpclient-1:3.1-4_patch_02.ep5.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el5", "package": "jboss-seam2-0:2.2.6.EAP5-22_patch_01.ep5.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1834", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el5", "package": "apache-cxf-0:2.2.12-14.patch_09.ep5.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el6", "package": "jakarta-commons-httpclient-1:3.1-4_patch_02.el6_5", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1321", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el6", "package": "jboss-seam2-0:2.2.6.EAP5-22_patch_01.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1834", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el6", "package": "apache-cxf-0:2.2.12-14.patch_09.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2014:1163", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6.3", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3", "release_date": "2014-09-04T00:00:00Z"}, {"advisory": "RHSA-2014:2020", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6.3", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:1162", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el5", "package": "httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5", "release_date": "2014-09-04T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el5", "package": "apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el5", "package": "wss4j-0:1.6.16-2.redhat_3.1.ep6.el5", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:1162", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6", "package": "httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6", "release_date": "2014-09-04T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6", "package": "apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6", "package": "wss4j-0:1.6.16-2.redhat_3.1.ep6.el6", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 6", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:1162", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7", "package": "httpcomponents-eap6-0:6-12.redhat_2.1.ep6.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7", "release_date": "2014-09-04T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7", "package": "apache-cxf-0:2.7.12-1.SP1_redhat_5.1.ep6.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2014:2019", "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7", "package": "wss4j-0:1.6.16-2.redhat_3.1.ep6.el7", "product_name": "Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7", "release_date": "2014-12-18T00:00:00Z"}, {"advisory": "RHSA-2016:1931", "cpe": "cpe:/a:redhat:jboss_fuse:6.2", "product_name": "Red Hat JBoss Fuse 6.2", "release_date": "2016-09-23T00:00:00Z"}, {"advisory": "RHSA-2015:1176", "cpe": "cpe:/a:redhat:jboss_fuse:6.2.0", "product_name": "Red Hat JBoss Fuse 6.2", "release_date": "2015-06-23T00:00:00Z"}, {"advisory": "RHSA-2015:0720", "cpe": "cpe:/a:redhat:jboss_fuse_service_works:6.0", "package": "httpclient", "product_name": "Red Hat JBoss Fuse Service Works 6.0", "release_date": "2015-03-24T00:00:00Z"}, {"advisory": "RHSA-2014:1904", "cpe": "cpe:/a:redhat:jboss_operations_network:3.3", "package": "httpclient", "product_name": "Red Hat JBoss Operations Network 3.3", "release_date": "2014-11-25T00:00:00Z"}, {"advisory": "RHSA-2014:1904", "cpe": "cpe:/a:redhat:jboss_operations_network:3.3", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Operations Network 3.3", "release_date": "2014-11-25T00:00:00Z"}, {"advisory": "RHSA-2015:1009", "cpe": "cpe:/a:redhat:jboss_enterprise_portal_platform:6.2", "package": "httpclient", "product_name": "Red Hat JBoss Portal 6.2", "release_date": "2015-05-14T00:00:00Z"}, {"advisory": "RHSA-2015:1888", "cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5.3", "package": "cxf", "product_name": "Red Hat JBoss SOA Platform 5.3", "release_date": "2015-10-12T00:00:00Z"}, {"advisory": "RHSA-2015:1888", "cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5.3", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss SOA Platform 5.3", "release_date": "2015-10-12T00:00:00Z"}, {"advisory": "RHSA-2015:0125", "cpe": "cpe:/a:redhat:jboss_enterprise_web_framework:2.7.0", "package": "httpclient", "product_name": "Red Hat JBoss Web Framework Kit 2.7", "release_date": "2015-02-04T00:00:00Z"}, {"advisory": "RHSA-2014:1322", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0", "package": "httpclient", "product_name": "Red Hat JBoss Web Platform 5.2", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1322", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0", "package": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Web Platform 5.2", "release_date": "2014-09-29T00:00:00Z"}, {"advisory": "RHSA-2014:1835", "cpe": "cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0", "product_name": "Red Hat JBoss Web Platform 5.2", "release_date": "2014-11-10T00:00:00Z"}, {"advisory": "RHSA-2022:0055", "cpe": "cpe:/a:redhat:openshift:4.10::el8", "impact": "moderate", "package": "jenkins-0:2.319.2.1643288987-1.el8", "product_name": "Red Hat OpenShift Container Platform 4.10", "release_date": "2022-03-10T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "activemq-0:5.9.0-6.redhat.611463.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "ImageMagick-0:6.7.2.7-5.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "jenkins-0:1.651.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "libcgroup-0:0.40.rc1-18.el6_8", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-0:1.16.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-broker-util-0:1.37.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-cron-0:1.25.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-diy-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-haproxy-0:1.31.6.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbosseap-0:2.27.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jbossews-0:1.35.5.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-0:1.29.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-jenkins-client-0:1.26.1.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mongodb-0:1.26.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-mysql-0:1.31.3.3-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-nodejs-0:1.33.1.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-perl-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-php-0:1.35.4.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-python-0:1.34.3.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-cartridge-ruby-0:1.32.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-msg-node-mcollective-0:1.30.2.2-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-proxy-0:1.26.3.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "openshift-origin-node-util-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rhc-0:1.38.7.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-admin-console-0:1.28.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-controller-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-frontend-haproxy-sni-proxy-0:0.5.2.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-msg-broker-mcollective-0:1.36.2.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-node-0:1.38.6.4-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2016:1773", "cpe": "cpe:/a:redhat:openshift:2.0::el6", "package": "rubygem-openshift-origin-routing-daemon-0:0.26.6.1-1.el6op", "product_name": "Red Hat OpenShift Enterprise 2.2", "release_date": "2016-08-24T00:00:00Z"}, {"advisory": "RHSA-2014:1082", "cpe": "cpe:/a:redhat:rhel_software_collections:1::el6", "package": "thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1", "product_name": "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6", "release_date": "2014-08-20T00:00:00Z"}, {"advisory": "RHSA-2014:1082", "cpe": "cpe:/a:redhat:rhel_software_collections:1::el6", "package": "thermostat1-httpcomponents-client-0:4.2.5-3.4.el6.1", "product_name": "Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS", "release_date": "2014-08-20T00:00:00Z"}, {"advisory": "RHSA-2015:0158", "cpe": "cpe:/a:redhat:rhev_manager:3", "package": "org.ovirt.engine-root-0:3.5.0-29", "product_name": "RHEV Manager version 3.5", "release_date": "2015-02-11T00:00:00Z"}], "bugzilla": {"description": "CXF: SSL hostname verification bypass, incomplete CVE-2012-6153 fix", "id": "1129074", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1129074"}, "csaw": false, "cvss": {"cvss_base_score": "5.8", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N", "status": "verified"}, "cvss3": {"cvss3_base_score": "4.8", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N", "status": "verified"}, "cwe": "CWE-297", "details": ["org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a \"CN=\" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the \"foo,CN=www.apache.org\" string in the O field.", "It was found that the fix for CVE-2012-6153 was incomplete: the code added to check that the server hostname matches the domain name in a subject's Common Name (CN) field in X.509 certificates was flawed. A man-in-the-middle attacker could use this flaw to spoof an SSL server using a specially crafted X.509 certificate."], "name": "CVE-2014-3577", "package_state": [{"cpe": "cpe:/a:redhat:openshift:1", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "OpenShift Enterprise 1"}, {"cpe": "cpe:/a:redhat:openshift:1", "fix_state": "Not affected", "package_name": "wagon-http", "product_name": "OpenShift Enterprise 1"}, {"cpe": "cpe:/a:redhat:developer_toolset:2.1", "fix_state": "Not affected", "package_name": "httpcomponents-client", "product_name": "Red Hat Developer Toolset 2.1"}, {"cpe": "cpe:/a:redhat:enterprise_linux:7::hypervisor", "fix_state": "Affected", "package_name": "redhat-support-plugin-rhev", "product_name": "Red Hat Enterprise Virtualization 3"}, {"cpe": "cpe:/a:redhat:enterprise_linux:7::hypervisor", "fix_state": "Affected", "package_name": "rhevm-dependencies", "product_name": "Red Hat Enterprise Virtualization 3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:5", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss BRMS 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:5", "fix_state": "Will not fix", "package_name": "httpclient", "product_name": "Red Hat JBoss BRMS 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:5", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss BRMS 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:5", "fix_state": "Will not fix", "package_name": "modeshape-client", "product_name": "Red Hat JBoss BRMS 5"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:6", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Data Grid 6"}, {"cpe": "cpe:/a:redhat:jboss_data_grid:6", "fix_state": "Affected", "package_name": "httpclient", "product_name": "Red Hat JBoss Data Grid 6"}, {"cpe": "cpe:/a:redhat:jboss_data_virtualization:6", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Data Virtualization 6"}, {"cpe": "cpe:/a:redhat:jboss_data_virtualization:6", "fix_state": "Fix deferred", "package_name": "modeshape-client", "product_name": "Red Hat JBoss Data Virtualization 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:4", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Enterprise Application Platform 4"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Enterprise Application Platform 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Fix deferred", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "amq-6", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "ewp-5", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Will not fix", "package_name": "fsf-2", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "fuse-6", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Will not fix", "package_name": "fuse-esb-4", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "fuse-esb-7", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Will not fix", "package_name": "fuse-mq-5.4", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "fuse-mq-5.5", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Affected", "package_name": "fuse-mq-7", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Fix deferred", "package_name": "jds-5", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Fix deferred", "package_name": "jds-6", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_web_server:1", "fix_state": "Fix deferred", "package_name": "jds-7", "product_name": "Red Hat JBoss Enterprise Web Server 1"}, {"cpe": "cpe:/a:redhat:jboss_fuse_service_works:6", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Fuse Service Works 6"}, {"cpe": "cpe:/a:redhat:jboss_operations_network:3", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Operations Network 3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_portal_platform:5", "fix_state": "Affected", "package_name": "httpclient", "product_name": "Red Hat JBoss Portal 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_portal_platform:5", "fix_state": "Affected", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss Portal 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_portal_platform:6", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss Portal 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:4.3", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat JBoss SOA Platform 4.3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5", "fix_state": "Affected", "package_name": "cxf", "product_name": "Red Hat JBoss SOA Platform 5"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5", "fix_state": "Affected", "package_name": "httpclient", "product_name": "Red Hat JBoss SOA Platform 5"}, {"cpe": "cpe:/a:redhat:openshift:2", "fix_state": "Affected", "package_name": "httpclient", "product_name": "Red Hat OpenShift Enterprise 2"}, {"cpe": "cpe:/a:redhat:openshift:2", "fix_state": "Not affected", "package_name": "wagon-http", "product_name": "Red Hat OpenShift Enterprise 2"}, {"cpe": "cpe:/a:redhat:network_satellite:5", "fix_state": "Will not fix", "package_name": "jakarta-commons-httpclient", "product_name": "Red Hat Satellite 5"}, {"cpe": "cpe:/a:redhat:satellite:6", "fix_state": "Affected", "package_name": "httpcomponents-client", "product_name": "Red Hat Satellite 6"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Affected", "package_name": "maven30-httpcomponents-client", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Affected", "package_name": "maven30-jakarta-commons-httpclient", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:storage:2.1", "fix_state": "Will not fix", "package_name": "rhevm-dependencies", "product_name": "Red Hat Storage 2.1"}, {"cpe": "cpe:/a:redhat:storage:3", "fix_state": "Will not fix", "package_name": "rhevm-dependencies", "product_name": "Red Hat Storage 3.0"}, {"cpe": "cpe:/o:redhat:rhev_hypervisor:4", "fix_state": "Affected", "package_name": "ovirt-engine-sdk-java", "product_name": "Red Hat Virtualization 4"}], "public_date": "2014-08-18T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2014-3577\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-3577"], "statement": "Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/solutions/1165533\nThis issue affects the versions of HttpComponents Client as shipped with Red Hat JBoss Data Grid 6 and Red Hat JBoss Data Virtualization 6; and ModeShape Client as shipped with Red Hat JBoss Data Virtualization 6. However, this flaw is not known to be exploitable under any supported scenario in Red Hat JBoss Data Grid 6 and JBoss Data Virtualization 6. A future update may address this issue.\nRed Hat JBoss Enterprise Application Platform 4, Red Hat JBoss SOA Platform 4, and Red Hat JBoss Web Server 1 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/\nFuse ESB 4, Fuse Message Broker 5.2, 5.3, 5.4 and Fuse Services Framework 2.3, 2.4 are now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having Important security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Fuse Product Life Cycle: https://access.redhat.com/support/policy/updates/fusesource/", "threat_severity": "Important"}