Known Vulnerabilities for 3scale Api Management by Redhat
Listed below are 9 of the newest known vulnerabilities associated with "3scale Api Management" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-0330 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run ma... | 7.8 - HIGH | 2022-03-25 | 2022-12-07 |
| CVE-2021-20252 | A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user... | 6.5 - MEDIUM | 2021-02-23 | 2021-02-27 |
| CVE-2021-3656 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (vi... | 8.8 - HIGH | 2022-03-04 | 2023-01-19 |
| CVE-2021-3609 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN ... | 7 - HIGH | 2022-03-03 | 2023-08-11 |
| CVE-2021-3412 | It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to b... | 7.3 - HIGH | 2021-06-01 | 2022-06-03 |
| CVE-2020-25634 | A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker... | 5.4 - MEDIUM | 2021-05-26 | 2022-10-21 |
| CVE-2020-14388 | A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not p... | 6.3 - MEDIUM | 2021-06-02 | 2022-07-25 |
| CVE-2019-14852 | A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this... | 7.5 - HIGH | 2021-03-18 | 2021-06-04 |
| CVE-2019-10216 | In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts ... | 7.8 - HIGH | 2019-11-27 | 2023-11-07 |