{
  "threat_severity" : "Moderate",
  "public_date" : "2020-04-28T00:00:00Z",
  "bugzilla" : {
    "description" : "wildfly-elytron: session fixation when using FORM authentication",
    "id" : "1825714",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1825714"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-384",
  "details" : [ "A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.", "A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability." ],
  "acknowledgement" : "Red Hat would like to thank Mark Banierink (Nedap) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "EAP-CD 20 Tech Preview",
    "release_date" : "2020-08-31T00:00:00Z",
    "advisory" : "RHSA-2020:3585",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_cd:20",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Red Hat Data Grid 7.3.7",
    "release_date" : "2020-09-17T00:00:00Z",
    "advisory" : "RHSA-2020:3779",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7.3",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Red Hat Fuse 7.9",
    "release_date" : "2021-08-11T00:00:00Z",
    "advisory" : "RHSA-2021:3140",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3642",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2.0",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3464",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3.0",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3637",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el6",
    "package" : "eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3638",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el7",
    "package" : "eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-elytron-web-0:1.2.5-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-glassfish-jsf-0:2.3.5-13.SP3_redhat_00011.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hal-console-0:3.0.23-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jackson-databind-0:2.9.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:2.3.5-7.SP2_redhat_00005.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-modules-0:1.8.10-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-server-migration-0:1.3.1-13.Final_redhat_00014.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-jboss-xnio-base-0:3.7.6-4.SP3_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-resteasy-0:3.6.1-10.SP9_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-weld-core-0:3.0.6-4.Final_redhat_00004.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-0:7.2.9-4.GA_redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-elytron-0:1.6.8-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8",
    "release_date" : "2020-09-07T00:00:00Z",
    "advisory" : "RHSA-2020:3639",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.2::el8",
    "package" : "eap7-wildfly-transaction-client-0:1.1.11-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3461",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el6",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el6eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3462",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el7",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-dom4j-0:2.1.3-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-elytron-web-0:1.6.2-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-glassfish-jsf-0:2.3.9-11.SP11_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-hal-console-0:3.2.9-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-hibernate-0:5.3.17-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-hibernate-validator-0:6.0.20-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-infinispan-0:9.4.19-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-ironjacamar-0:1.4.22-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-annotations-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-core-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-databind-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-jaxrs-providers-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-modules-base-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jackson-modules-java8-0:2.10.4-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-genericjms-0:2.0.6-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-jsf-api_2.3_spec-0:3.0.0-4.SP04_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-logmanager-0:2.1.15-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-server-migration-0:1.7.1-7.Final_redhat_00009.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-jboss-xnio-base-0:3.7.8-1.SP1_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-netty-0:4.1.48-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-undertow-0:2.0.30-4.SP4_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-0:7.3.2-4.GA_redhat_00002.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-common-0:1.5.2-1.Final_redhat_00002.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-elytron-0:1.10.7-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8",
    "release_date" : "2020-08-17T00:00:00Z",
    "advisory" : "RHSA-2020:3463",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.3::el8",
    "package" : "eap7-wildfly-http-client-0:1.0.22-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.4.2",
    "release_date" : "2020-08-18T00:00:00Z",
    "advisory" : "RHSA-2020:3501",
    "cpe" : "cpe:/a:redhat:jboss_single_sign_on:7.4",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "RHDM 7.9.0",
    "release_date" : "2020-11-05T00:00:00Z",
    "advisory" : "RHSA-2020:4960",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7.9",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "RHPAM 7.9.0",
    "release_date" : "2020-11-05T00:00:00Z",
    "advisory" : "RHSA-2020:4961",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7.9",
    "package" : "wildfly-elytron"
  }, {
    "product_name" : "Text-Only RHOAR",
    "release_date" : "2020-09-02T00:00:00Z",
    "advisory" : "RHSA-2020:3539",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "wildfly-elytron",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat OpenShift Application Runtimes",
    "fix_state" : "Affected",
    "package_name" : "wildfly-elytron",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-10714\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-10714" ],
  "name" : "CVE-2020-10714",
  "mitigation" : {
    "value" : "This attack is dependent on the attacker being able to create a session and the victim accessing the session before the session expires, we do have a 15 minute session timeout by default but the attacker could also keep this alive by say sending in a request every five minutes.\nThe server by default supports session tracking by URL and Cookie, if the web.xml is updated to support COOKIE only the exploit is not possible by sharing the link.\n~~~\n<session-config>\n<tracking-mode>URL</tracking-mode>\n</session-config>\n~~~\nTO\n~~~\n<session-config>\n<tracking-mode>COOKIE</tracking-mode>\n</session-config>\n~~~",
    "lang" : "en:us"
  },
  "csaw" : false
}