语言:
https://access.redhat.com/articles/7137769
https://access.redhat.com/errata/RHSA-2026:70228
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2455350
https://bugzilla.redhat.com/show_bug.cgi?id=2458638
https://bugzilla.redhat.com/show_bug.cgi?id=2477930
https://bugzilla.redhat.com/show_bug.cgi?id=2477945
https://bugzilla.redhat.com/show_bug.cgi?id=2478013
https://bugzilla.redhat.com/show_bug.cgi?id=2480601
https://bugzilla.redhat.com/show_bug.cgi?id=2480637
https://bugzilla.redhat.com/show_bug.cgi?id=2480638
https://bugzilla.redhat.com/show_bug.cgi?id=2480729
https://bugzilla.redhat.com/show_bug.cgi?id=2483131
https://bugzilla.redhat.com/show_bug.cgi?id=2483133
https://bugzilla.redhat.com/show_bug.cgi?id=2483135
https://bugzilla.redhat.com/show_bug.cgi?id=2483136
https://bugzilla.redhat.com/show_bug.cgi?id=2483138
https://bugzilla.redhat.com/show_bug.cgi?id=2483140
https://bugzilla.redhat.com/show_bug.cgi?id=2484703
https://bugzilla.redhat.com/show_bug.cgi?id=2488304
https://bugzilla.redhat.com/show_bug.cgi?id=2488309
https://bugzilla.redhat.com/show_bug.cgi?id=2490628
https://bugzilla.redhat.com/show_bug.cgi?id=2491620
https://bugzilla.redhat.com/show_bug.cgi?id=2492010
https://bugzilla.redhat.com/show_bug.cgi?id=2492015
https://bugzilla.redhat.com/show_bug.cgi?id=2492016
https://bugzilla.redhat.com/show_bug.cgi?id=2492627
https://bugzilla.redhat.com/show_bug.cgi?id=2494771
https://bugzilla.redhat.com/show_bug.cgi?id=2500653
https://bugzilla.redhat.com/show_bug.cgi?id=2503101
https://bugzilla.redhat.com/show_bug.cgi?id=2503103
https://bugzilla.redhat.com/show_bug.cgi?id=2505422
https://bugzilla.redhat.com/show_bug.cgi?id=2505911
https://bugzilla.redhat.com/show_bug.cgi?id=2507482
https://bugzilla.redhat.com/show_bug.cgi?id=2510195
https://bugzilla.redhat.com/show_bug.cgi?id=2510722
https://bugzilla.redhat.com/show_bug.cgi?id=2511026
https://bugzilla.redhat.com/show_bug.cgi?id=2515377
https://bugzilla.redhat.com/show_bug.cgi?id=2521309
https://issues.redhat.com/browse/JBEAP-32314
https://issues.redhat.com/browse/JBEAP-32869
https://issues.redhat.com/browse/JBEAP-33162
https://issues.redhat.com/browse/JBEAP-33185
https://issues.redhat.com/browse/JBEAP-33236
https://issues.redhat.com/browse/JBEAP-33237
https://issues.redhat.com/browse/JBEAP-33288
https://issues.redhat.com/browse/JBEAP-33363
https://issues.redhat.com/browse/JBEAP-33405
https://issues.redhat.com/browse/JBEAP-33409
https://issues.redhat.com/browse/JBEAP-33413
https://issues.redhat.com/browse/JBEAP-33449
https://issues.redhat.com/browse/JBEAP-33459
https://issues.redhat.com/browse/JBEAP-33501
https://issues.redhat.com/browse/JBEAP-33579
https://issues.redhat.com/browse/JBEAP-33616
https://issues.redhat.com/browse/JBEAP-33640
https://issues.redhat.com/browse/JBEAP-33683
https://issues.redhat.com/browse/JBEAP-33848
https://issues.redhat.com/browse/JBEAP-33871
https://issues.redhat.com/browse/JBEAP-33904
https://issues.redhat.com/browse/JBEAP-33925
https://issues.redhat.com/browse/JBEAP-33967
https://issues.redhat.com/browse/JBEAP-33968
https://issues.redhat.com/browse/JBEAP-33973
https://issues.redhat.com/browse/JBEAP-34018
https://issues.redhat.com/browse/JBEAP-34095
https://issues.redhat.com/browse/JBEAP-34096
https://issues.redhat.com/browse/JBEAP-34111
https://issues.redhat.com/browse/JBEAP-34161
https://issues.redhat.com/browse/JBEAP-34222
https://issues.redhat.com/browse/JBEAP-34521
http://www.nessus.org/u?29b6d808
严重性: High
ID: 348800
文件名: redhat-RHSA-2026-70228.nasl
版本: 1.1
类型: Local
代理: unix
发布时间: 2026/9/22
最近更新时间: 2026/9/22
支持的传感器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
风险因素: Medium
分数: 6.9
百分位: 96.81
Vendor Severity: Important
风险因素: Critical
基本分数: 10
时间分数: 7.8
矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS 分数来源: CVE-2026-49875
风险因素: Critical
基本分数: 9.8
时间分数: 8.8
矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间矢量: CVSS:3.0/E:P/RL:O/RC:C
风险因素: High
Base Score: 8.7
Threat Score: 7.7
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS 分数来源: CVE-2026-68494
CPE: cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-jmail, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pg, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pkix, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-prov, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-util, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle, p-cpe:/a:redhat:enterprise_linux:eap8-codemodel, p-cpe:/a:redhat:enterprise_linux:eap8-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformat-yaml, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformats-text, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-module-jakarta-xmlbind-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb, p-cpe:/a:redhat:enterprise_linux:eap8-jaxbintros, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-api, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-common-tools, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-jaxws-undertow-httpspi, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-spi, p-cpe:/a:redhat:enterprise_linux:eap8-jsf-impl, p-cpe:/a:redhat:enterprise_linux:eap8-log4j, p-cpe:/a:redhat:enterprise_linux:eap8-neethi, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-nimbus-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap8-parsson, p-cpe:/a:redhat:enterprise_linux:eap8-relaxng-datatype, p-cpe:/a:redhat:enterprise_linux:eap8-rngom, p-cpe:/a:redhat:enterprise_linux:eap8-saaj-impl, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-txw2, p-cpe:/a:redhat:enterprise_linux:eap8-undertow, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-ws-commons-xmlschema, p-cpe:/a:redhat:enterprise_linux:eap8-xml-security, p-cpe:/a:redhat:enterprise_linux:eap8-xsom
必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu
可利用: true
易利用性: Exploits are available
补丁发布日期: 2026/9/22
漏洞发布日期: 2026/4/15
CVE: CVE-2026-10832, CVE-2026-14180, CVE-2026-15554, CVE-2026-15555, CVE-2026-15560, CVE-2026-15561, CVE-2026-15562, CVE-2026-15563, CVE-2026-15565, CVE-2026-15567, CVE-2026-3505, CVE-2026-44417, CVE-2026-46581, CVE-2026-49362, CVE-2026-49363, CVE-2026-49364, CVE-2026-49875, CVE-2026-50632, CVE-2026-54512, CVE-2026-54513, CVE-2026-54515, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-5680, CVE-2026-57967, CVE-2026-59649, CVE-2026-59889, CVE-2026-59899, CVE-2026-62243, CVE-2026-68494, CVE-2026-69152, CVE-2026-73508, CVE-2026-85511, CVE-2026-86404