BlackTreeIndependent security intelligence
← Back to the CVE catalogue
Full vulnerability report · 2025
CVE-2025-9230High confidence

Out-of-bounds read & write in RFC 3211 KEK Unwrap

OpenSSL · OpenSSL

7.5HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
Distribution package intelligence

Ubuntu vendor package status

Canonical’s release and source-package findings are shown separately from local repository availability.

1 package state
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Ubuntu releaseSource packageVendor stateFixed versionEvidence
Ubuntu 24.04 LTSnoble · standard archiveopensslVendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.3.0.13-0ubuntu3.6Canonical record ↗Source updated 9 Sept 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

8 current
CVE-2025-9230 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityopenssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
17 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes
  • multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes
  • multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes
  • multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes
  • multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes
  • multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes
  • acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • openssl as a component of Red Hat Enterprise Linux 6
  • openssl-devel as a component of Red Hat Enterprise Linux 6
Summary
A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI).
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
SSA-082556 · CSAF 2.0 · revision 7 · interimSiemens ProductCERTSSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5
5 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) >= V3.1.5
  • SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) >= V3.1.5
Summary
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
SSA-585531 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-585531: Multiple Vulnerabilities in SIDIS Secured SmartPlug before V7.26.0310
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIDIS Secured SmartPlug < V7.26.0310
Summary
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Update to V7.26.0310 or later version
SSA-253495 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-253495: Multiple Vulnerabilities in SINEC OS before V4.0
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • RUGGEDCOM RST2428P (6GK6242-6PA00)
Summary
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Update to V4.0 or later version
SSA-032379 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-032379: Multiple Vulnerabilities in SIMATIC CN 4100 Before V5.0
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC CN 4100
Summary
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Update to V5.0 or later version
SSA-265688 · CSAF 2.0 · revision 13 · interimSiemens ProductCERTSSA-265688: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Summary
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
SSA-485750 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIDIS Prime
Summary
An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Update to V4.0.800 or later version
SSA-089022 · CSAF 2.0 · revision 2 · interimSiemens ProductCERTSSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3
16 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • RUGGEDCOM RST2428P (6GK6242-6PA00)
  • SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family
  • SCALANCE XCH328 (6GK5328-4TS01-2EC2)
  • SCALANCE XCM324 (6GK5324-8TS01-2AC2)
  • SCALANCE XCM328 (6GK5328-4TS01-2AC2)
  • SCALANCE XCM332 (6GK5332-0GA01-2AC2)
  • SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3)
  • SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3)
  • SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3)
  • SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3)
  • SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3)
  • SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3)
Summary
An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.
Remediation
Update to V3.3 or later version
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2025-31729

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

What

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

Why

The product reads data past the end, or before the beginning, of the intended buffer.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

Why

The product reads data past the end, or before the beginning, of the intended buffer.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Out-of-bounds Read → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-125

CWE-125: Out-of-bounds Read. The product reads data past the end, or before the beginning, of the intended buffer.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-125
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-W-2026-2189Dell PowerProtect Data Domain: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um seine Privilegien zu erhöhen um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, um Informationen offenzulegen, und um Dateien zu manipulieren.

Official advisory
BSI · German · WID-SEC-W-2026-1194Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2026-0647SAP Patchday März 2026: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder andere, nicht näher spezifizierte Angriffe durchzuführen.

Official advisory
BSI · German · WID-SEC-W-2026-0544IBM QRadar SIEM: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren oder andere nicht näher spezifizierte Angriffe durchzuführen, darunter potenzielle Codeausführung oder Speicherbeschädigung.

Official advisory
BSI · German · WID-SEC-W-2026-0349Dell Avamar und NetWorker: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell Avamar und Dell NetWorker ausnutzen, um Angriffe zu starten, die die Integrität, Vertraulichkeit und Verfügbarkeit von Systemen beeinträchtigen.

Official advisory
BSI · German · WID-SEC-W-2026-0168Oracle MySQL: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2026-0167Oracle PeopleSoft: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle PeopleSoft ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2026-0163Oracle Financial Services Applications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2026-1730Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff

Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.

Official advisory
BSI · German · WID-SEC-W-2026-1200Oracle JD Edwards: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit und Verfügbarkeit zu gefährden.

Official advisory
BSI · German · WID-SEC-W-2025-2166OpenSSL und LibreSSL: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL und LibreSSL ausnutzen, um potentiell beliebigen Code auszuführen, einen Denial of Service-Zustand zu verursachen und vertrauliche Informationen offenzulegen.

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0565Multiples vulnérabilités dans les produits Siemens

CVERecord?id=CVE-2025-53066 Référence CVE CVE-2025-55752 https://www.cve.org/CVERecord?id=CVE-2025-55752 Référence CVE CVE-2025-55754 https://www.cve.org/CVERecord?id=CVE-2025-55754 Référence CVE CVE-2025-6021 https://www.cve.org/CVERecord?id=CVE-2025-6021 Référence CVE CVE-2025-6052 https://www.cve.org/CVERecord?id=CVE-2025-6052 Référence CVE CVE-2025-61748 https://www.cve.org/CVERecord?id=CVE-2025-61748 Référence CVE CVE-2025-61795 https://www.cve.org/CVERecord?id=CVE-2025-61795 Référence CVE CVE-2025-7425 https://www.cve.org/CVERecord?id=CVE-2025-7425 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9820 https://www.cve.org/CVERecord?id=CVE-2025-9820 Référence CVE CVE-2026-21925 https://www.cve.org/CVERecord?id=CVE-2026-21925 Référence CVE CVE-2026-21932 https://www.cve.org/CVERecord?id=CVE-2026-21932 Référence CVE CVE-2026-21933 https://www.cve.org/CVERecord?id=CVE-2026-21933 Référence CVE CVE-2026-21945 https://www.cve.org/CVERecord?id=CVE-2026-21945 Référence CVE CVE-2026-21947 https://www.cve.org/CVERecord?id=CVE-202

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0556Multiples vulnérabilités dans les produits VMware

ve.org/CVERecord?id=CVE-2025-6921 Référence CVE CVE-2025-69534 https://www.cve.org/CVERecord?id=CVE-2025-69534 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8713 https://www.cve.org/CVERecord?id=CVE-2025-8713 Référence CVE CVE-2025-8714 https://www.cve.org/CVERecord?id=CVE-2025-8714 Référence CVE CVE-2025-8715 https://www.cve.org/CVERecord?id=CVE-2025-8715 Référence CVE CVE-2025-8869 https://www.cve.org/CVERecord?id=CVE-2025-8869 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9820 https://www.cve.org/CVERecord?id=CVE-2025-9820 Référence CVE CVE-2026-0672 https://www.cve.org/CVERecord?id=CVE-2026-0672 Référence CVE CVE-2026-0846 https://www.cve.org/CVERecord?id=CVE-2026-0846 Référence CVE CVE-2026-0861 https://www.cve.org/CVERecord?id=CVE-2026-0861 Référence CVE CVE-2026-0865 https://www.cve.org/CVERecord?id=CVE-2026-0865 Référence CVE CVE-2026-0897 https://www.cve.org/CVERecord?id=CVE-2026-0897 Référence CVE CVE-2026-0915 https://www.cve.org/CVERecord?id=CVE-2026-0915 Ré

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMware

e.org/CVERecord?id=CVE-2025-71237 Référence CVE CVE-2025-71238 https://www.cve.org/CVERecord?id=CVE-2025-71238 Référence CVE CVE-2025-7519 https://www.cve.org/CVERecord?id=CVE-2025-7519 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8277 https://www.cve.org/CVERecord?id=CVE-2025-8277 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8677 https://www.cve.org/CVERecord?id=CVE-2025-8677 Référence CVE CVE-2025-8746 https://www.cve.org/CVERecord?id=CVE-2025-8746 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9301 https://www.cve.org/CVERecord?id=CVE-2025-9301 Référence CVE CVE-2025-9403 https://www.cve.org/CVERecord?id=CVE-2025-9403 Référence CVE CVE-2025-9820 https://www.cve.org/CVERecord?id=CVE-2025-9820 Référence CVE CVE-2026-0964 https://www.cve.org/CVERecord?id=CVE-2026-0964 Référence CVE CVE-2026-0965 https://www.cve.org/CVERecord?id=CVE-2026-0965 Référence CVE CVE-2026-0966 https://www.cve.org/CVERecord?id=CVE-2026-0966 Ré

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMware

g/CVERecord?id=CVE-2025-71235 Référence CVE CVE-2025-71236 https://www.cve.org/CVERecord?id=CVE-2025-71236 Référence CVE CVE-2025-71237 https://www.cve.org/CVERecord?id=CVE-2025-71237 Référence CVE CVE-2025-71238 https://www.cve.org/CVERecord?id=CVE-2025-71238 Référence CVE CVE-2025-7519 https://www.cve.org/CVERecord?id=CVE-2025-7519 Référence CVE CVE-2025-8277 https://www.cve.org/CVERecord?id=CVE-2025-8277 Référence CVE CVE-2025-8677 https://www.cve.org/CVERecord?id=CVE-2025-8677 Référence CVE CVE-2025-8746 https://www.cve.org/CVERecord?id=CVE-2025-8746 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9301 https://www.cve.org/CVERecord?id=CVE-2025-9301 Référence CVE CVE-2025-9403 https://www.cve.org/CVERecord?id=CVE-2025-9403 Référence CVE CVE-2025-9820 https://www.cve.org/CVERecord?id=CVE-2025-9820 Référence CVE CVE-2026-0964 https://www.cve.org/CVERecord?id=CVE-2026-0964 Référence CVE CVE-2026-0965 https://www.cve.org/CVERecord?id=CVE-2026-0965 Référence CVE CVE-2026-0966 https://www.cve.org/CVERecord?id=CVE-2026-0966 Ré

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunk

e.org/CVERecord?id=CVE-2025-69420 Référence CVE CVE-2025-69421 https://www.cve.org/CVERecord?id=CVE-2025-69421 Référence CVE CVE-2025-6965 https://www.cve.org/CVERecord?id=CVE-2025-6965 Référence CVE CVE-2025-8114 https://www.cve.org/CVERecord?id=CVE-2025-8114 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8556 https://www.cve.org/CVERecord?id=CVE-2025-8556 Référence CVE CVE-2025-8885 https://www.cve.org/CVERecord?id=CVE-2025-8885 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9714 https://www.cve.org/CVERecord?id=CVE-2025-9714 Référence CVE CVE-2025-9820 https://www.cve.org/CVERecord?id=CVE-2025-9820 Référence CVE CVE-2025-9951 https://www.cve.org/CVERecord?id=CVE-2025-9951 Référence CVE CVE-2026-20162 https://www.cve.org/CVERecord?id=CVE-2026-20162 Référence CVE CVE-2026-20163 https://www.cve.org/CVERecord?id=CVE-2026-20163 Référence CVE CVE-2026-20164 https://www.cve.org/CVERecord?id=CVE-2026-20

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0256Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection SQL (SQLi).

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0224Multiples vulnérabilités dans les produits IBM

d?id=CVE-2025-68973 Référence CVE CVE-2025-69223 https://www.cve.org/CVERecord?id=CVE-2025-69223 Référence CVE CVE-2025-69224 https://www.cve.org/CVERecord?id=CVE-2025-69224 Référence CVE CVE-2025-69225 https://www.cve.org/CVERecord?id=CVE-2025-69225 Référence CVE CVE-2025-69226 https://www.cve.org/CVERecord?id=CVE-2025-69226 Référence CVE CVE-2025-69227 https://www.cve.org/CVERecord?id=CVE-2025-69227 Référence CVE CVE-2025-69228 https://www.cve.org/CVERecord?id=CVE-2025-69228 Référence CVE CVE-2025-69229 https://www.cve.org/CVERecord?id=CVE-2025-69229 Référence CVE CVE-2025-69230 https://www.cve.org/CVERecord?id=CVE-2025-69230 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2026-1188 https://www.cve.org/CVERecord?id=CVE-2026-1188 Référence CVE CVE-2026-1615 https://www.cve.org/CVERecord?id=CVE-2026-1615 Référence CVE CVE-2026-21860 https://www.cve.org/CVERecord?id=CVE-2026-21860 Référence CVE CVE-2026-21925 https://www.cve.org/CVERecord?id=CVE-2026-21925 Référence CVE CVE-2026-21932 https://www.cve.org/CVERecord?id=CVE-2026-21932 Référence CVE CVE-2026-21933 https://www.cve.org/CVERecord?id=CVE-2026-21933 Référence CVE CVE-2026-21945 https://www.cve.org/CVERecord?id=CVE-2026-21945 Référence CVE CVE-2026-22610 https://www.cve.org/CVERecord?id=CVE-2

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-8714 Référence CVE CVE-2025-8715 https://www.cve.org/CVERecord?id=CVE-2025-8715 Référence CVE CVE-2025-8732 https://www.cve.org/CVERecord?id=CVE-2025-8732 Référence CVE CVE-2025-8851 https://www.cve.org/CVERecord?id=CVE-2025-8851 Référence CVE CVE-2025-8869 https://www.cve.org/CVERecord?id=CVE-2025-8869 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-8959 https://www.cve.org/CVERecord?id=CVE-2025-8959 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9165 https://www.cve.org/CVERecord?id=CVE-2025-9165 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9714 https://www.cve.org/CVERecord?id=CVE-2025-9714 Référence CVE CVE-2025-9900 https://www.cve.org/CVERecord?id=CVE-2025-9900 Référence CVE CVE-2026-0672 https://www.cve.org/CVERecord?id=CVE-2026-0672 Référence CVE CVE-2026-0861 https://www.cve.org/CVERecord?id=CVE-2026-0861 Référence CVE CVE-2026-0865 https://www.cve.org/CVERecord?id=CVE-2026-0865 Référence CVE CVE-2026-0900 https://www.cve.org/CVERecord?id=CVE-2026-0900 Référence CVE CVE-2026-0902 https://www.cve.org/CVERecord?id=CVE-2026-0902 Ré

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-7425 Référence CVE CVE-2025-8058 https://www.cve.org/CVERecord?id=CVE-2025-8058 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8556 https://www.cve.org/CVERecord?id=CVE-2025-8556 Référence CVE CVE-2025-8732 https://www.cve.org/CVERecord?id=CVE-2025-8732 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9714 https://www.cve.org/CVERecord?id=CVE-2025-9714 Référence CVE CVE-2026-0672 https://www.cve.org/CVERecord?id=CVE-2026-0672 Référence CVE CVE-2026-0861 https://www.cve.org/CVERecord?id=CVE-2026-0861 Référence CVE CVE-2026-0865 https://www.cve.org/CVERecord?id=CVE-2026-0865 Référence CVE CVE-2026-0915 https://www.cve.org/CVERecord?id=CVE-2026-0915 Référence CVE CVE-2026-0988 https://www.cve.org/CVERecord?id=CVE-2026-0988 Référence CVE CVE-2026-0989 https://www.cve.org/CVERecord?id=CVE-2026-0989 Ré

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0188Multiples vulnérabilités dans les produits Splunk

d?id=CVE-2025-58183 Référence CVE CVE-2025-58185 https://www.cve.org/CVERecord?id=CVE-2025-58185 Référence CVE CVE-2025-58186 https://www.cve.org/CVERecord?id=CVE-2025-58186 Référence CVE CVE-2025-58187 https://www.cve.org/CVERecord?id=CVE-2025-58187 Référence CVE CVE-2025-58188 https://www.cve.org/CVERecord?id=CVE-2025-58188 Référence CVE CVE-2025-58189 https://www.cve.org/CVERecord?id=CVE-2025-58189 Référence CVE CVE-2025-61723 https://www.cve.org/CVERecord?id=CVE-2025-61723 Référence CVE CVE-2025-61724 https://www.cve.org/CVERecord?id=CVE-2025-61724 Référence CVE CVE-2025-61725 https://www.cve.org/CVERecord?id=CVE-2025-61725 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2026-20137 https://www.cve.org/CVERecord?id=CVE-2026-20137 Référence CVE CVE-2026-20138 https://www.cve.org/CVERecord?id=CVE-2026-20138 Référence CVE CVE-2026-20139 https://www.cve.org/CVERecord?id=CVE-2026-20139 Référence CVE CVE-2026-20140 https://www.cve.org/CVERecord?id=CVE-2026-20140 Référence CVE CVE-2026-20141 https://www.cve.org/CVERecord?id=CVE-2026-20141 Référence CVE CVE-2026-20142 https://www.cve.org/CVERecord?id=CVE-2026-20142 Référence CVE CVE-2026-20143 https://www.cve.org/CVERecord?id=CVE-2026-20143 Référence CVE CVE-2026-20144 https://www.cve.org/CVERecord?id=C

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0112Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-7424 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8713 https://www.cve.org/CVERecord?id=CVE-2025-8713 Référence CVE CVE-2025-8714 https://www.cve.org/CVERecord?id=CVE-2025-8714 Référence CVE CVE-2025-8715 https://www.cve.org/CVERecord?id=CVE-2025-8715 Référence CVE CVE-2025-8885 https://www.cve.org/CVERecord?id=CVE-2025-8885 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-8959 https://www.cve.org/CVERecord?id=CVE-2025-8959 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2026-1484 https://www.cve.org/CVERecord?id=CVE-2026-1484 Référence CVE CVE-2026-1485 https://www.cve.org/CVERecord?id=CVE-2026-1485 Référence CVE CVE-2026-1489 https://www.cve.org/CVERecord?id=CVE-2026-1489 Référence CVE CVE-2026-21441 https://www.cve.org/CVERecord?id=CVE-2026-21441 Référence CVE CVE-2026-24842 https://www.cve.org/CVERecord?id=CVE-2026-24842 Référence CVE CVE-2026-24881 https://www.cve.org/CVERecord?id=CVE-2026-24

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0101Multiples vulnérabilités dans les produits Siemens

ve.org/CVERecord?id=CVE-2025-4138 Référence CVE CVE-2025-4330 https://www.cve.org/CVERecord?id=CVE-2025-4330 Référence CVE CVE-2025-4373 https://www.cve.org/CVERecord?id=CVE-2025-4373 Référence CVE CVE-2025-4435 https://www.cve.org/CVERecord?id=CVE-2025-4435 Référence CVE CVE-2025-4516 https://www.cve.org/CVERecord?id=CVE-2025-4516 Référence CVE CVE-2025-4517 https://www.cve.org/CVERecord?id=CVE-2025-4517 Référence CVE CVE-2025-59375 https://www.cve.org/CVERecord?id=CVE-2025-59375 Référence CVE CVE-2025-6141 https://www.cve.org/CVERecord?id=CVE-2025-6141 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Gestion détaillée du document le 29 janvier 2026 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0071Multiples vulnérabilités dans Oracle PeopleSoft

De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory
CERT-FR · French · CERTFR-2026-AVI-0070Multiples vulnérabilités dans Oracle MySQL

De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1057Multiples vulnérabilités dans les produits VMware

rg/CVERecord?id=CVE-2025-6170 Référence CVE CVE-2025-62372 https://www.cve.org/CVERecord?id=CVE-2025-62372 Référence CVE CVE-2025-62426 https://www.cve.org/CVERecord?id=CVE-2025-62426 Référence CVE CVE-2025-65106 https://www.cve.org/CVERecord?id=CVE-2025-65106 Référence CVE CVE-2025-6965 https://www.cve.org/CVERecord?id=CVE-2025-6965 Référence CVE CVE-2025-7709 https://www.cve.org/CVERecord?id=CVE-2025-7709 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8732 https://www.cve.org/CVERecord?id=CVE-2025-8732 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9714 https://www.cve.org/CVERecord?id=CVE-2025-9714 Gestion détaillée du document le 02 décembre 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systè

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1054Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-4330 Référence CVE CVE-2025-4435 https://www.cve.org/CVERecord?id=CVE-2025-4435 Référence CVE CVE-2025-4516 https://www.cve.org/CVERecord?id=CVE-2025-4516 Référence CVE CVE-2025-4517 https://www.cve.org/CVERecord?id=CVE-2025-4517 Référence CVE CVE-2025-6069 https://www.cve.org/CVERecord?id=CVE-2025-6069 Référence CVE CVE-2025-6297 https://www.cve.org/CVERecord?id=CVE-2025-6297 Référence CVE CVE-2025-8058 https://www.cve.org/CVERecord?id=CVE-2025-8058 Référence CVE CVE-2025-8114 https://www.cve.org/CVERecord?id=CVE-2025-8114 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Gestion détaillée du document le 01 décembre 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1036Multiples vulnérabilités dans les produits VMware

Record?id=CVE-2025-6069 Référence CVE CVE-2025-61723 https://www.cve.org/CVERecord?id=CVE-2025-61723 Référence CVE CVE-2025-61724 https://www.cve.org/CVERecord?id=CVE-2025-61724 Référence CVE CVE-2025-61725 https://www.cve.org/CVERecord?id=CVE-2025-61725 Référence CVE CVE-2025-61748 https://www.cve.org/CVERecord?id=CVE-2025-61748 Référence CVE CVE-2025-61795 https://www.cve.org/CVERecord?id=CVE-2025-61795 Référence CVE CVE-2025-64329 https://www.cve.org/CVERecord?id=CVE-2025-64329 Référence CVE CVE-2025-8114 https://www.cve.org/CVERecord?id=CVE-2025-8114 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Gestion détaillée du document le 24 novembre 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-8732 Référence CVE CVE-2025-8851 https://www.cve.org/CVERecord?id=CVE-2025-8851 Référence CVE CVE-2025-8885 https://www.cve.org/CVERecord?id=CVE-2025-8885 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-8961 https://www.cve.org/CVERecord?id=CVE-2025-8961 Référence CVE CVE-2025-9086 https://www.cve.org/CVERecord?id=CVE-2025-9086 Référence CVE CVE-2025-9092 https://www.cve.org/CVERecord?id=CVE-2025-9092 Référence CVE CVE-2025-9165 https://www.cve.org/CVERecord?id=CVE-2025-9165 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9288 https://www.cve.org/CVERecord?id=CVE-2025-9288 Référence CVE CVE-2025-9340 https://www.cve.org/CVERecord?id=CVE-2025-9340 Référence CVE CVE-2025-9341 https://www.cve.org/CVERecord?id=CVE-2025-9341 Référence CVE CVE-2025-9390 https://www.cve.org/CVERecord?id=CVE-2025-9390 Référence CVE CVE-2025-9403 https://www.cve.org/CVERecord?id=CVE-2025-9403 Référence CVE CVE-2025-9640 https://www.cve.org/CVERecord?id=CVE-2025-9640 Ré

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0967Multiples vulnérabilités dans les produits VMware

cve.org/CVERecord?id=CVE-2025-61921 Référence CVE CVE-2025-6242 https://www.cve.org/CVERecord?id=CVE-2025-6242 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8291 https://www.cve.org/CVERecord?id=CVE-2025-8291 Référence CVE CVE-2025-8713 https://www.cve.org/CVERecord?id=CVE-2025-8713 Référence CVE CVE-2025-8714 https://www.cve.org/CVERecord?id=CVE-2025-8714 Référence CVE CVE-2025-8715 https://www.cve.org/CVERecord?id=CVE-2025-8715 Référence CVE CVE-2025-8885 https://www.cve.org/CVERecord?id=CVE-2025-8885 Référence CVE CVE-2025-8916 https://www.cve.org/CVERecord?id=CVE-2025-8916 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Gestion détaillée du document le 05 novembre 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0938Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2025-6965 Référence CVE CVE-2025-7345 https://www.cve.org/CVERecord?id=CVE-2025-7345 Référence CVE CVE-2025-7425 https://www.cve.org/CVERecord?id=CVE-2025-7425 Référence CVE CVE-2025-8176 https://www.cve.org/CVERecord?id=CVE-2025-8176 Référence CVE CVE-2025-8194 https://www.cve.org/CVERecord?id=CVE-2025-8194 Référence CVE CVE-2025-8713 https://www.cve.org/CVERecord?id=CVE-2025-8713 Référence CVE CVE-2025-8714 https://www.cve.org/CVERecord?id=CVE-2025-8714 Référence CVE CVE-2025-8715 https://www.cve.org/CVERecord?id=CVE-2025-8715 Référence CVE CVE-2025-8941 https://www.cve.org/CVERecord?id=CVE-2025-8941 Référence CVE CVE-2025-9230 https://www.cve.org/CVERecord?id=CVE-2025-9230 Référence CVE CVE-2025-9231 https://www.cve.org/CVERecord?id=CVE-2025-9231 Référence CVE CVE-2025-9232 https://www.cve.org/CVERecord?id=CVE-2025-9232 Référence CVE CVE-2025-9288 https://www.cve.org/CVERecord?id=CVE-2025-9288 Référence CVE CVE-2025-9900 https://www.cve.org/CVERecord?id=CVE-2025-9900 Gestion détaillée du document le 30 octobre 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défen

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0835Multiples vulnérabilités dans OpenSSL

De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0229Kwetsbaarheden verholpen in Siemens producten

A moderate severity vulnerability (CVE-2025-9230) in OpenSSL's CMS password-based encryption causes out-of-bounds read/write in RFC 3211 KEK unwrap, potentially leading to crashes or memory corruption, with low exploitation likelihood and multiple vendor patches released.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0147Kwetsbaarheden verholpen in Siemens-producten

Multiple OpenSSL vulnerabilities including CVE-2025-9230 cause out-of-bounds read/write in RFC 3211 KEK unwrap during CMS password-based decryption, potentially leading to crashes or code execution, with moderate severity and low exploit likelihood due to rare usage.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0091Kwetsbaarheden verholpen in SAP-producten

Multiple OpenSSL versions have an out-of-bounds read/write vulnerability in RFC 3211 KEK unwrap related to password-based CMS decryption, with moderate severity due to low exploit likelihood, affecting products including NetApp, Oracle, and SAP components.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0079Kwetsbaarheden verholpen in Siemens producten

Multiple OpenSSL versions have an out-of-bounds read/write vulnerability in RFC 3211 KEK unwrap related to password-based CMS decryption, with moderate severity due to low exploit likelihood, affecting products including NetApp, Oracle, and SAP components.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0032Kwetsbaarheden verholpen in Oracle MySQL

Multiple vulnerabilities related to out-of-bounds read and write issues in OpenSSL affect various products, with moderate severity assessments and low likelihood of successful exploitation.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0028Kwetsbaarheden verholpen in Oracle Analytics

Multiple vulnerabilities related to out-of-bounds read and write issues in OpenSSL affect various products, with moderate severity assessments and low likelihood of successful exploitation.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0025Kwetsbaarheden verholpen in Oracle Financial Services

Multiple vulnerabilities related to out-of-bounds read and write issues in OpenSSL affect various products, with moderate severity assessments and low likelihood of successful exploitation.

Official advisory
NCSC-NL · Dutch · NCSC-2026-0023Kwetsbaarheden verholpen in Oracle PeopleSoft

Multiple vulnerabilities related to out-of-bounds read and write issues in OpenSSL affect various products, with moderate severity assessments and low likelihood of successful exploitation.

Official advisory
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client
Fixed
openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 622 more
Action
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 30 Sept 2025 · Last source change 14 Jul 2026, 12:39 UTC · CWE-125 · Out-of-bounds Read

CVE recordCVE.org · 5.2
CVSS sourceCISA ADP
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2025-31729
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD not scheduled

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates →
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    After
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 622 more
    Red Hat Product Security
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    After
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    Red Hat Product Security
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-placement-container as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    After
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/placement-rhel9 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    Red Hat Product Security
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-placement-container as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; rhcos as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    After
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-placement-container as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    Red Hat Product Security
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-placement-container as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    After
    multicloud-operators-foundation.src as a component of Multicluster Engine for Kubernetes; multicluster-engine-placement-container as a component of Multicluster Engine for Kubernetes; multicluster-engine-work-container as a component of Multicluster Engine for Kubernetes; multicluster-engine/hypershift-addon-rhel9-operator as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-operator-rhel8 as a component of Multicluster Engine for Kubernetes; multicluster-engine/registration-rhel8 as a component of Multicluster Engine for Kubernetes; acm-cluster-manager-addon-manager-controller-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; acm-multicluster-engine-operator-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; rhcos as a component of Red Hat OpenShift Container Platform 4; puppet-agent.src as a component of Red Hat Satellite Client · Fixed: openssl-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-debuginfo-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-devel-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS); openssl-libs-1:1.0.2k-26.el7_9.1.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS); jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-debuginfo-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; jbcs-httpd24-openssl-devel-1:1.1.1k-21.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server; and 610 more
    Red Hat Product Security
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2025-9230 · cve.blacktree.nl