{
  "threat_severity" : "Moderate",
  "public_date" : "2011-05-10T00:00:00Z",
  "bugzilla" : {
    "description" : "apr: unconstrained recursion in apr_fnmatch",
    "id" : "703390",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=703390"
  },
  "cvss" : {
    "cvss_base_score" : "4.3",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
    "status" : "verified"
  },
  "details" : [ "Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd." ],
  "acknowledgement" : "Red Hat would like to thank Maksymilian Arciemowicz for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "ant-0:1.7.1-13.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "antlr-0:2.7.7-7.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "bcel-0:5.2-8.1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "cglib-0:2.2-5.1.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "dom4j-0:1.6.1-11.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "ecj-1:3.3.1.1-3.2.2.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "glassfish-jaf-0:1.1.0-6.1.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "glassfish-javamail-0:1.4.2-0.4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "glassfish-jsf-0:1.2_13-2.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "hibernate3-1:3.3.2-1.5.GA_CP04.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "hibernate3-annotations-0:3.4.0-3.3.GA_CP04.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "hibernate3-entitymanager-0:3.4.0-4.3.GA_CP04.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "httpd22-0:2.2.17-14.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-beanutils-0:1.8.0-4.1.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-chain-0:1.2-2.2.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-codec-0:1.3-9.1.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-collections-0:3.2.1-4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-daemon-1:1.0.5-1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-dbcp-0:1.2.1-16.4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-digester-0:1.8.1-8.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-el-0:1.0-19.2.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-fileupload-1:1.1.1-7.4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-httpclient-1:3.1-1.1.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-io-0:1.4-1.3.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-launcher-0:1.1-4.6.1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-logging-0:1.1.1-0.4.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-logging-jboss-0:1.1-10.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-modeler-0:2.0-4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-pool-0:1.3-11.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-commons-validator-0:1.3.1-7.5.1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-oro-0:2.0.8-3.3.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jakarta-taglibs-standard-0:1.1.1-9.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "javassist-0:3.12.0-1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jboss-common-core-0:2.2.17-1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jboss-common-logging-jdk-0:2.1.2-1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jboss-common-logging-spi-0:2.1.2-1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jboss-javaee-0:5.0.1-2.9.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jcommon-0:1.0.16-1.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "jfreechart-0:1.0.13-2.3.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "log4j-0:1.2.14-18.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "mod_cluster-0:1.0.10-2.GA_CP01.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "mod_cluster-native-0:1.0.10-2.GA_CP01.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "mod_jk-0:1.2.31-1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "mx4j-1:3.0.1-9.3.4.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "objectweb-asm-0:3.1-5.3.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "regexp-0:1.5-1.2.1.jdk6.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "struts12-0:1.2.9-3.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat5-0:5.5.33-14_patch_04.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat6-0:6.0.32-15_patch_03.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat-jkstatus-ant-0:1.2.31-2.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "tomcat-native-0:1.1.20-2.0.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "xalan-j2-0:2.7.1-5.3_patch_04.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "xerces-j2-0:2.9.1-3.patch01.1.ep5.el4"
  }, {
    "product_name" : "JBEWS 1.0 for RHEL 4",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el4",
    "package" : "xml-commons-1:1.3.04-7.12.ep5.el4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 4",
    "release_date" : "2011-05-11T00:00:00Z",
    "advisory" : "RHSA-2011:0507",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4",
    "package" : "apr-0:0.9.4-25.el4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2011-05-11T00:00:00Z",
    "advisory" : "RHSA-2011:0507",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "apr-0:1.2.7-11.el5_6.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2011-05-11T00:00:00Z",
    "advisory" : "RHSA-2011:0507",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "apr-0:1.3.9-3.el6_0.1"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "ant-0:1.7.1-13.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "antlr-0:2.7.7-7.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "cglib-0:2.2-5.1.1.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "dom4j-0:1.6.1-11.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "ecj3-1:3.3.1.1-3.1.1.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "glassfish-jsf-0:1.2_13-3.1.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "hibernate3-1:3.3.2-1.4.GA_CP04.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "hibernate3-annotations-0:3.4.0-3.2.GA_CP04.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "hibernate3-entitymanager-0:3.4.0-4.3.GA_CP04.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "httpd-0:2.2.17-11.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-beanutils-0:1.8.0-4.1.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-chain-0:1.2-2.2.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-codec-0:1.3-9.2.1.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-collections-0:3.2.1-4.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-daemon-1:1.0.5-1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-dbcp-0:1.2.1-16.4.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-digester-0:1.8.1-8.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-fileupload-1:1.1.1-7.4.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-httpclient-1:3.1-1.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-io-0:1.4-1.3.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-logging-0:1.1.1-0.4.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-logging-jboss-0:1.1-10.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-pool-0:1.3-11.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-commons-validator-0:1.3.1-7.5.2.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-oro-0:2.0.8-3.3.2.1.1.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jakarta-taglibs-standard-0:1.1.1-9.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "javassist-0:3.12.0-1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jboss-common-core-0:2.2.17-1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jboss-common-logging-jdk-0:2.1.2-1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jboss-common-logging-spi-0:2.1.2-1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jboss-javaee-0:5.0.1-2.9.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jcommon-0:1.0.16-1.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "jfreechart-0:1.0.13-2.3.2.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "mod_cluster-0:1.0.10-2.1.GA_CP01.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "mod_cluster-native-0:1.0.10-2.1.GA_CP01.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "mod_jk-0:1.2.31-1.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "objectweb-asm-0:3.1-5.3.1.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "struts12-0:1.2.9-3.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat5-0:5.5.33-16_patch_04.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat6-0:6.0.32-15.1_patch_03.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat-jkstatus-ant-0:1.2.31-2.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "tomcat-native-0:1.1.20-2.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "xalan-j2-0:2.7.1-5.3_patch_04.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "xerces-j2-0:2.9.1-3.patch01.1.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 5",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el5",
    "package" : "xml-commons-0:1.3.04-7.10.jdk6.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "ant-0:1.7.1-14.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "antlr-0:2.7.7-7.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "cglib-0:2.2-5.4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "dom4j-0:1.6.1-11.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "ecj3-1:3.3.1.1-4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "glassfish-jsf-0:1.2_13-3.1.4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "hibernate3-1:3.3.2-1.8.GA_CP04.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "hibernate3-annotations-0:3.4.0-3.5.GA_CP04.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.3.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "hibernate3-entitymanager-0:3.4.0-4.4.GA_CP04.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "httpd-0:2.2.17-11.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-beanutils-0:1.8.0-9.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-chain-0:1.2-2.2.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-codec-0:1.3-12.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-collections-0:3.2.1-4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-daemon-1:1.0.5-1.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-dbcp-0:1.2.1-16.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-digester-0:1.8.1-8.1.1.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-fileupload-1:1.1.1-7.5.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-httpclient-1:3.1-1.2.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-io-0:1.4-4.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-logging-0:1.1.1-1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-logging-jboss-0:1.1-10.2.2.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-pool-0:1.3-15.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-commons-validator-0:1.3.1-7.5.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-oro-0:2.0.8-7.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jakarta-taglibs-standard-0:1.1.1-12.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "javassist-0:3.12.0-3.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jboss-common-core-0:2.2.17-1.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jboss-common-logging-jdk-0:2.1.2-1.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jboss-common-logging-spi-0:2.1.2-1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jboss-javaee-0:5.0.1-2.9.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jcommon-0:1.0.16-1.2.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "jfreechart-0:1.0.13-2.3.2.1.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "mod_cluster-0:1.0.10-2.2.GA_CP01.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "mod_cluster-native-0:1.0.10-2.1.1.GA_CP01.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "mod_jk-0:1.2.31-1.1.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "objectweb-asm31-0:3.1-12.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "struts12-0:1.2.9-3.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "tomcat5-0:5.5.33-15_patch_04.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "tomcat6-0:6.0.32-14_patch_03.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "tomcat-jkstatus-ant-0:1.2.31-2.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "tomcat-native-0:1.1.20-2.1.2.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "xalan-j2-0:2.7.1-5.3_patch_04.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "xerces-j2-0:2.9.1-8.patch01.1.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1 for RHEL 6",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0897",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1::el6",
    "package" : "xml-commons-0:1.3.04-7.14.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Web Server 1.0",
    "release_date" : "2011-06-22T00:00:00Z",
    "advisory" : "RHSA-2011:0896",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2011-0419\nhttps://nvd.nist.gov/vuln/detail/CVE-2011-0419" ],
  "name" : "CVE-2011-0419",
  "mitigation" : {
    "value" : "mod_autoindex can be configured to ignore request query arguments provided by the client by adding IgnoreClient option to the IndexOptions directive:\nhttp://httpd.apache.org/docs/2.2/mod/mod_autoindex.html#indexoptions.ignoreclient",
    "lang" : "en:us"
  },
  "csaw" : false
}