VDB
RHSA-2011:0175
RHSA-2011:0175
PUBLISHED
JBoss Web Framework Kit 1.0.0 contains a security flaw and should no longer be used. This update removes the JBoss Web Framework Kit 1.0.0 packages. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat JBoss Web Framework Kit 1.0.0 for RHEL 5 Server | ||
| jboss | ||
| Red Hat JBoss Web Framework Kit 5.0.0 for RHEL 4 ES | ||
| Red Hat JBoss Web Framework Kit 5.0.0 for RHEL 4 AS |
Timeline
- Jan 25, 2011 CVE Published
- Oct 21, 2023 PoC Published
- Nov 17, 2024 PoC Published
- Nov 21, 2025 CVE Updated
- Apr 5, 2026 Distribution Patch
- Apr 5, 2026 Distribution Patch
- Apr 5, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/jbossnetwork/ url
- http://docs.redhat.com/docs/en-US/JBoss_Web_Framework_Kit/1.1/html/Release_Notes_1.1.0/Installation_Notes.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=606706 url
- https://security.access.redhat.com/data/csaf/v2/advisories/2011/rhsa-2011_0175.json advisory
- https://access.redhat.com/errata/RHSA-2011:0175 advisory
- https://access.redhat.com/security/updates/classification/#moderate url