{
  "threat_severity" : "Important",
  "public_date" : "2020-07-15T00:00:00Z",
  "bugzilla" : {
    "description" : "tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS",
    "id" : "1857024",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1857024"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.", "A flaw was found in Apache Tomcat, where the payload length in a WebSocket frame was not correctly validated. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. The highest threat from this vulnerability is to system availability." ],
  "statement" : "Red Hat Certificate System 10.0 as well as Red Hat Enterprise Linux 8's Identity Management, are using a vulnerable version of Tomcat, bundled into the pki-servlet-engine component. However, there is no entry point for WebSockets, thus it is not possible to trigger the flaw in a supported setup. A future update may fix the code. Similarly, Red Hat OpenStack Platform 13 does not ship with WebSocket functionality enabled by default.",
  "affected_release" : [ {
    "product_name" : "EAP 6.4.24 release",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5458",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2020-09-29T00:00:00Z",
    "advisory" : "RHSA-2020:4004",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "tomcat-0:7.0.76-15.el7"
  }, {
    "product_name" : "Red Hat Fuse 7.9",
    "release_date" : "2021-08-11T00:00:00Z",
    "advisory" : "RHSA-2021:3140",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "tomcat",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 async",
    "release_date" : "2020-08-10T00:00:00Z",
    "advisory" : "RHSA-2020:3382",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6.4",
    "package" : "jbossweb"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5",
    "release_date" : "2020-08-10T00:00:00Z",
    "advisory" : "RHSA-2020:3383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el5",
    "package" : "jbossweb-0:7.5.31-2.Final_redhat_2.1.ep6.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2020-08-10T00:00:00Z",
    "advisory" : "RHSA-2020:3383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossweb-0:7.5.31-2.Final_redhat_2.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5459",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "jbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2020-08-10T00:00:00Z",
    "advisory" : "RHSA-2020:3383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossweb-0:7.5.31-2.Final_redhat_2.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7",
    "release_date" : "2022-06-30T00:00:00Z",
    "advisory" : "RHSA-2022:5460",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el7",
    "package" : "jbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el7"
  }, {
    "product_name" : "Red Hat JBoss Web Server 3.1",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3305",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:3.1",
    "package" : "tomcat"
  }, {
    "product_name" : "Red Hat JBoss Web Server 3 for RHEL 6",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3303",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6",
    "package" : "tomcat7-0:7.0.70-41.ep7.el6"
  }, {
    "product_name" : "Red Hat JBoss Web Server 3 for RHEL 6",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3303",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el6",
    "package" : "tomcat8-0:8.0.36-45.ep7.el6"
  }, {
    "product_name" : "Red Hat JBoss Web Server 3 for RHEL 7",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3303",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7",
    "package" : "tomcat7-0:7.0.70-41.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Web Server 3 for RHEL 7",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3303",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:3.1::el7",
    "package" : "tomcat8-0:8.0.36-45.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Web Server 5.3 on RHEL 6",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3306",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5.3::el6",
    "package" : "jws5-tomcat-0:9.0.30-5.redhat_6.1.el6jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 5.3 on RHEL 7",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3306",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5.3::el7",
    "package" : "jws5-tomcat-0:9.0.30-5.redhat_6.1.el7jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 5.3 on RHEL 8",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3306",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5.3::el8",
    "package" : "jws5-tomcat-0:9.0.30-5.redhat_6.1.el8jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server (JWS) 5.3",
    "release_date" : "2020-08-04T00:00:00Z",
    "advisory" : "RHSA-2020:3308",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:5.3",
    "package" : "tomcat"
  }, {
    "product_name" : "Red Hat Runtimes Spring Boot 2.2.6",
    "release_date" : "2020-09-23T00:00:00Z",
    "advisory" : "RHSA-2020:3806",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0",
    "package" : "tomcat"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Decision Manager 7",
    "fix_state" : "Not affected",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "tomcat6",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "pki-deps:10.6/pki-servlet-engine",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "tomcat",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jbossweb",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:6"
  }, {
    "product_name" : "Red Hat JBoss Data Virtualization 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jbossweb",
    "cpe" : "cpe:/a:redhat:jboss_data_virtualization:6"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6",
    "fix_state" : "Out of support scope",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Out of support scope",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:10",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Will not fix",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:13",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "tomcat",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Out of support scope",
    "package_name" : "rh-java-common-tomcat",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-13935\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-13935\nhttp://mail-archives.apache.org/mod_mbox/tomcat-announce/202007.mbox/%3C39e4200c-6f4e-b85d-fe4b-a9c2bd5fdc3d%40apache.org%3E\nhttp://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.0-M7\nhttp://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.105\nhttp://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.57\nhttp://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.37" ],
  "name" : "CVE-2020-13935",
  "mitigation" : {
    "value" : "Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.",
    "lang" : "en:us"
  },
  "csaw" : false
}