{
  "threat_severity" : "Low",
  "public_date" : "2009-06-03T00:00:00Z",
  "bugzilla" : {
    "description" : "tomcat6 Information disclosure in authentication classes",
    "id" : "503978",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=503978"
  },
  "cvss" : {
    "cvss_base_score" : "5.0",
    "cvss_scoring_vector" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
    "status" : "verified"
  },
  "details" : [ "Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter." ],
  "affected_release" : [ {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hibernate3-1:3.2.4-1.SP1_CP08.0jpp.ep1.2.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hibernate3-annotations-0:3.3.1-1.10.GA_CP01.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hibernate3-commons-annotations-0:3.0.0-1jpp.ep1.5.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hibernate3-entitymanager-0:3.3.2-2.4.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hibernate3-validator-0:3.0.0-1jpp.ep1.8.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "hsqldb-1:1.8.0.8-2.patch02.1jpp.ep1.2.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jakarta-slide-webdavclient-0:2.1-9.2.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jbossas-0:4.2.0-4.GA_CP07.5.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jboss-cache-0:1.4.1-6.SP13.1.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jboss-remoting-0:2.2.3-2.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jboss-seam-0:1.2.1-1.ep1.19.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jbossts-1:4.2.3-1.SP5_CP05.1jpp.ep1.1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jbossweb-0:2.0.0-6.CP11.0jpp.ep1.1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "jgroups-1:2.4.6-1.ep1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "rh-eap-docs-0:4.2.0-5.GA_CP07.ep1.1.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1144",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el4",
    "package" : "xerces-j2-0:2.7.1-9jpp.ep1.2.el4"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "hibernate3-1:3.2.4-1.SP1_CP08.0jpp.ep1.2.3.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "hibernate3-annotations-0:3.3.1-1.10.1GA_CP01.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "hibernate3-commons-annotations-0:3.0.0-1jpp.ep1.5.2.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "hibernate3-entitymanager-0:3.3.2-2.4.1.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "hibernate3-validator-0:3.0.0-1jpp.ep1.8.3.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jakarta-slide-webdavclient-0:2.1-9.2.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jbossas-0:4.2.0-4.GA_CP07.5.1.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jboss-cache-0:1.4.1-6.SP13.1.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jboss-remoting-0:2.2.3-2.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jboss-seam-0:1.2.1-1.ep1.13.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jbossts-1:4.2.3-1.SP5_CP05.1jpp.ep1.1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jbossweb-0:2.0.0-6.CP11.0jpp.ep1.1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "jgroups-1:2.4.6-1.ep1.el5"
  }, {
    "product_name" : "JBEAP 4.2.0 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1143",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.2.0::el5",
    "package" : "rh-eap-docs-0:4.2.0-5.GA_CP07.ep1.1.1.el5"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2009-09-21T00:00:00Z",
    "advisory" : "RHSA-2009:1454",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat5-0:5.5.23-1.patch07.19.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2009-10-14T00:00:00Z",
    "advisory" : "RHSA-2009:1506",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat6-0:6.0.18-11.3.ep5.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "ant-0:1.6.5-1jpp_1rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "avalon-logkit-0:1.2-2jpp_4rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "axis-0:1.2.1-1jpp_3rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "classpathx-jaf-0:1.0-2jpp_6rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "classpathx-mail-0:1.1.1-2jpp_8rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "geronimo-specs-0:1.0-0.M4.1jpp_10rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "jakarta-commons-modeler-0:2.0-3jpp_2rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "log4j-0:1.2.12-1jpp_1rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "mx4j-1:3.0.1-1jpp_4rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "pcsc-lite-0:1.3.3-3.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-ca-0:7.3.0-20.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-java-tools-0:7.3.0-10.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-kra-0:7.3.0-14.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-manage-0:7.3.0-19.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-native-tools-0:7.3.0-6.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-ocsp-0:7.3.0-13.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "rhpki-tks-0:7.3.0-13.el4"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "tomcat5-0:5.5.23-0jpp_4rh.16"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "xerces-j2-0:2.7.1-1jpp_1rh"
  }, {
    "product_name" : "Red Hat Certificate System 7.3",
    "release_date" : "2010-08-04T00:00:00Z",
    "advisory" : "RHSA-2010:0602",
    "cpe" : "cpe:/a:redhat:certificate_system:7.3",
    "package" : "xml-commons-0:1.3.02-2jpp_1rh"
  }, {
    "product_name" : "Red Hat Developer Suite V.3",
    "release_date" : "2009-11-09T00:00:00Z",
    "advisory" : "RHSA-2009:1563",
    "cpe" : "cpe:/a:redhat:rhel_developer_suite:3",
    "package" : "tomcat5-0:5.5.23-0jpp_18rh"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2009-07-21T00:00:00Z",
    "advisory" : "RHSA-2009:1164",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "tomcat5-0:5.5.23-0jpp.7.el5_3.2"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "glassfish-jaxb-0:2.1.4-1.11.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hibernate3-1:3.2.4-1.SP1_CP08.0jpp.ep1.2.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hibernate3-annotations-0:3.3.1-1.10.GA_CP01.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hibernate3-commons-annotations-0:3.0.0-1jpp.ep1.5.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hibernate3-entitymanager-0:3.3.2-2.4.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hibernate3-validator-0:3.0.0-1jpp.ep1.8.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "hsqldb-1:1.8.0.8-2.patch02.1jpp.ep1.2.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jakarta-slide-webdavclient-0:2.1-9.2.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossas-0:4.3.0-4.GA_CP05.6.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jboss-cache-0:1.4.1-6.SP13.1.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jboss-messaging-0:1.4.0-2.SP3_CP08.1.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jboss-remoting-0:2.2.3-2.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.15.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossts-1:4.2.3-1.SP5_CP05.1jpp.ep1.1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossweb-0:2.0.0-6.CP11.0jpp.ep1.1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossws-0:2.0.1-3.SP2_CP06.3.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossws-common-0:1.0.0-2.GA_CP04.1.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossws-framework-0:2.0.1-1.GA_CP04.2.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jbossws-spi-0:1.0.0-1.GA_CP02.1.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "jgroups-1:2.4.6-1.ep1.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "rh-eap-docs-0:4.3.0-5.GA_CP05.ep1.2.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1146",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el4",
    "package" : "xerces-j2-0:2.7.1-9jpp.ep1.2.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "glassfish-jaxb-0:2.1.4-1.11.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "hibernate3-1:3.2.4-1.SP1_CP08.0jpp.ep1.2.3.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "hibernate3-annotations-0:3.3.1-1.10.1GA_CP01.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "hibernate3-commons-annotations-0:3.0.0-1jpp.ep1.5.2.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "hibernate3-entitymanager-0:3.3.2-2.4.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "hibernate3-validator-0:3.0.0-1jpp.ep1.8.3.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jakarta-slide-webdavclient-0:2.1-9.2.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossas-0:4.3.0-4.GA_CP05.6.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jboss-cache-0:1.4.1-6.SP13.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jboss-messaging-0:1.4.0-2.SP3_CP08.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jboss-remoting-0:2.2.3-2.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.11.el5.1"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossts-1:4.2.3-1.SP5_CP05.1jpp.ep1.1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossweb-0:2.0.0-6.CP11.0jpp.ep1.1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossws-0:2.0.1-3.SP2_CP06.3.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossws-common-0:1.0.0-2.GA_CP04.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossws-framework-0:2.0.1-1.GA_CP04.2.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jbossws-spi-0:1.0.0-1.GA_CP02.1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "jgroups-1:2.4.6-1.ep1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5",
    "release_date" : "2009-07-06T00:00:00Z",
    "advisory" : "RHSA-2009:1145",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4.3.0::el5",
    "package" : "rh-eap-docs-0:4.3.0-5.GA_CP05.ep1.2.1.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2009-09-21T00:00:00Z",
    "advisory" : "RHSA-2009:1454",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat5-0:5.5.23-0jpp.9.6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2009-10-14T00:00:00Z",
    "advisory" : "RHSA-2009:1506",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat6-0:6.0.18-12.0.ep5.el5"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 5.2",
    "release_date" : "2009-11-30T00:00:00Z",
    "advisory" : "RHSA-2009:1616",
    "cpe" : "cpe:/a:redhat:network_satellite:5.2::el4",
    "package" : "tomcat5-0:5.5.23-0jpp_18rh"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 5.3",
    "release_date" : "2009-11-30T00:00:00Z",
    "advisory" : "RHSA-2009:1616",
    "cpe" : "cpe:/a:redhat:network_satellite:5.3::el4",
    "package" : "tomcat5-0:5.5.23-0jpp_18rh"
  }, {
    "product_name" : "RHAPS Version 2 for RHEL 4",
    "release_date" : "2009-11-09T00:00:00Z",
    "advisory" : "RHSA-2009:1562",
    "cpe" : "cpe:/a:redhat:rhel_application_server:2",
    "package" : "tomcat5-0:5.5.23-0jpp_4rh.16"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2009-0580\nhttps://nvd.nist.gov/vuln/detail/CVE-2009-0580" ],
  "name" : "CVE-2009-0580",
  "csaw" : false
}