CVE-2022-4039 PUBLISHED CVSS 8 HIGH

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.

EPSS 0.12% · 31.2th percentile

Risk Scores

CVSS v3.1
8
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
31.2th percentile

Affected Products

VendorProductVersions
Red HatRHEL-8 based Middleware Containers7.6-20
redhatsingle_sign-on7.0
redhatopenshift_container_platform4.9, 4.10
redhatopenshift_container_platform_for_linuxone4.9, 4.10
redhatopenshift_container_platform_for_power4.10, 4.9
Red HatRed Hat Single Sign-On 7
redhatopenshift_container_platform_for_ibm_z4.9, 4.10

Timeline

References

Open in Interactive Console →