[WID-SEC-2022-0607] Red Hat FUSE: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 07.07.2022 Stand UPDATE 10.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung Red Hat Fuse ist eine Open-Source-Integrationsplattform, die auf Apache Camel basiert. Produkte UPDATE 09.08.2026 IBM Operational Decision Manager UPDATE 18.11.2025 Atlassian Bitbucket <10.0.2 Atlassian Bitbucket <8.19.25 (LTS) Atlassian Bitbucket <9.4.13 (LTS) UPDATE 27.10.2025 IBM QRadar SIEM UPDATE 04.05.2025 Red Hat JBoss Enterprise Application Platform <7.3.13 UPDATE 28.04.2025 Red Hat JBoss Enterprise Application Platform <7.1.10 UPDATE 20.03.2024 IBM Spectrum Protect Plus 10.1 UPDATE 04.02.2024 EMC Avamar UPDATE 25.10.2022 IBM QRadar SIEM 7.5 IBM QRadar SIEM 7.4 UPDATE 16.10.2022 NetApp ActiveIQ Unified Manager UPDATE 31.07.2022 Debian Linux UPDATE 28.07.2022 Hitachi Ops Center UPDATE 19.07.2022 Red Hat Enterprise Linux 07.07.2022 Red Hat FUSE <7.11.0 Angriff Angriff Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple critical vulnerabilities in Red Hat FUSE (CVSS Base Score 9.8) allow remote attackers to execute arbitrary code, disclose information, cause denial of service, bypass security controls, manipulate data, and escalate privileges. The specific attack vector is not detailed, but the threat is applicable to Red Hat FUSE versions prior to 7.11.0. A patch is available, requiring an upgrade to Red Hat FUSE 7.11.0, and mitigations are noted for affected downstream products.