Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2020-07-31 CVE-2020-14337 Information Exposure Through an Error Message vulnerability in Redhat Ansible Tower 3.0.0
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes.
network
low complexity
redhat CWE-209
5.8
2020-07-31 CVE-2020-14334 Unspecified vulnerability in Redhat Satellite 6.0
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files.
local
low complexity
redhat
8.8
2020-07-31 CVE-2020-10731 Unspecified vulnerability in Redhat Openstack Platform 15.0/16.0/16.1
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled.
network
low complexity
redhat
critical
9.9
2020-07-29 CVE-2020-14316 A flaw was found in kubevirt 0.29 and earlier.
network
low complexity
kubevirt redhat
critical
9.9
2020-07-29 CVE-2020-15707 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow.
6.4
2020-07-29 CVE-2020-15706 Use After Free vulnerability in multiple products
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass.
6.4
2020-07-29 CVE-2020-15705 Improper Verification of Cryptographic Signature vulnerability in multiple products
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed.
6.4
2020-07-24 CVE-2020-14307 Unspecified vulnerability in Redhat products
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server.
network
low complexity
redhat
6.5
2020-07-24 CVE-2020-14297 Unspecified vulnerability in Redhat products
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable.
network
low complexity
redhat
6.5
2020-07-14 CVE-2020-15719 Improper Certificate Validation vulnerability in multiple products
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support.
network
high complexity
openldap redhat opensuse mcafee oracle CWE-295
4.2