VDB
CVE-2021-44549
CVE-2021-44549
PUBLISHED
CVSS 8.699999809265137 HIGH
Es existiert eine Schwachstelle in Apache Sling. Der Fehler besteht aufgrund einer unsachgemäßen Zertifikatsvalidierung in der Komponente Commons Messaging Mail. Ein entfernter Angreifer kann diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen.
EPSS 0.24% · 47.7th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.24%
47.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | |
| Red Hat | Red Hat Enterprise Linux AI | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Quarkus <3.8.6.SP1 | |
| Open Source | Open Source Keycloak <26.0.4 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat OpenStack 16.2 | |
| Splunk | Splunk Splunk Enterprise <10.0.1 | |
| NetApp | NetApp ActiveIQ Unified Manager | |
| Splunk | Splunk Splunk Enterprise <9.2.8 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform <7.4.24 | |
| Apache | Apache Sling <2.0 | |
| Apache | Apache Camel | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Quarkus <3.2.12.SP1 | |
| Red Hat | Red Hat OpenShift Serverless Logic <1.35.0 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform <7.4.23 | |
| Red Hat | Red Hat Enterprise Linux | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| IBM | IBM License Metric Tool | |
| Red Hat | Red Hat Enterprise Linux Cryostat 3 | |
| Amazon | Amazon Linux 2 |
…and 5 more
Exploit Intelligence
Timeline
- Dec 14, 2021 CVE Published
- Dec 15, 2021 EPSS Score
- Dec 22, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 7, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 3, 2022 EPSS Score
- May 27, 2022 EPSS Score
- Jul 21, 2022 EPSS Score
- Sep 14, 2022 EPSS Score
- Dec 31, 2022 EPSS Score
- Feb 24, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3147.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3147 advisory
- https://access.redhat.com/errata/RHSA-2024:7670 advisory
- https://access.redhat.com/errata/RHSA-2024:7676 advisory
- https://access.redhat.com/errata/RHSA-2024:7972 advisory
- https://access.redhat.com/errata/RHSA-2024:8093 advisory
- https://access.redhat.com/errata/RHSA-2024:8329 advisory
- https://access.redhat.com/errata/RHSA-2024:9571 advisory
- https://alas.aws.amazon.com/AL2/ALAS-2024-2693.html advisory
- https://security.netapp.com/advisory/ntap-20241213-0010/ advisory
- https://access.redhat.com/errata/RHSA-2025:0664 advisory
- https://access.redhat.com/errata/RHSA-2025:7620 advisory
- https://ubuntu.com/security/notices/USN-7629-2 advisory
- https://advisory.splunk.com//advisories/SVD-2025-1007 advisory
- https://access.redhat.com/errata/RHSA-2025:20052 advisory
- https://access.redhat.com/errata/RHSA-2025:20057 advisory
- https://access.redhat.com/errata/RHSA-2026:4915 advisory
- https://access.redhat.com/errata/RHSA-2026:4916 advisory
- https://access.redhat.com/errata/RHSA-2026:4924 advisory
- https://access.redhat.com/errata/RHSA-2026:4917 advisory
…and 11 more