{
  "schema_version": "1.7.0",
  "id": "RHSA-2010:0938",
  "related": [],
  "upstream": [
    "CVE-2010-3708",
    "CVE-2010-3862",
    "CVE-2010-3878"
  ],
  "published": "2024-09-15T18:39:31Z",
  "modified": "2025-11-22T10:28:42Z",
  "summary": "Red Hat Security Advisory: JBoss Enterprise Application Platform 4.3.0.CP09 update",
  "affected": [
    {
      "package": {
        "name": "glassfish-jaxb",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/glassfish-jaxb"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.1.4-1.17.patch04.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "glassfish-jaxws",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/glassfish-jaxws"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.1.1-1jpp.ep1.13.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "hibernate3",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/hibernate3"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1:3.2.4-1.SP1_CP11.0jpp.ep2.0.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "hibernate3-annotations",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/hibernate3-annotations"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:3.3.1-2.0.GA_CP04.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "hibernate3-annotations-javadoc",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/hibernate3-annotations-javadoc"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:3.3.1-2.0.GA_CP04.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "hibernate3-javadoc",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/hibernate3-javadoc"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1:3.2.4-1.SP1_CP11.0jpp.ep2.0.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "javassist",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/javassist"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:3.9.0-2.ep1.1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-common",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-common"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.2-1.ep1.1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-messaging",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-messaging"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.4.0-4.SP3_CP11.1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-remoting",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-remoting"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.2.3-4.SP3.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-seam",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-seam"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.22.el5.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-seam-docs",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-seam-docs"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.22.el5.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-seam2",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-seam2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.0.2.FP-1.ep1.26.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jboss-seam2-docs",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jboss-seam2-docs"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.0.2.FP-1.ep1.26.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossas",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossas"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:4.3.0-8.GA_CP09.2.1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossas-4.3.0.GA_CP09-bin",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossas-4.3.0.GA_CP09-bin"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:4.3.0-8.GA_CP09.2.1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossas-client",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossas-client"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:4.3.0-8.GA_CP09.2.1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossts",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossts"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1:4.2.3-2.SP5_CP10.1jpp.ep1.1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossweb",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossweb"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.0.0-7.CP15.0jpp.ep1.1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossws",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossws"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.0.1-6.SP2_CP09.2.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jbossws-common",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jbossws-common"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.0.0-3.GA_CP06.1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "jgroups",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/jgroups"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1:2.4.9-1.ep1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "quartz",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/quartz"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.5.2-1jpp.patch01.ep1.4.2.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "rh-eap-docs",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/rh-eap-docs"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:4.3.0-8.GA_CP09.ep1.3.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "rh-eap-docs-examples",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/rh-eap-docs-examples"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:4.3.0-8.GA_CP09.ep1.3.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "xalan-j2",
        "ecosystem": "Red Hat:jboss_enterprise_application_platform:4.3.0::el5",
        "purl": "pkg:rpm/redhat/xalan-j2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:2.7.1-4.ep1.1.el5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2010:0938"
    },
    {
      "type": "ARTICLE",
      "url": "https://access.redhat.com/security/updates/classification/#important"
    },
    {
      "type": "ARTICLE",
      "url": "http://docs.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3/html-single/Release_Notes_CP09/index.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=604617"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=633859"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=638236"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=641389"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2010/rhsa-2010_0938.json"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2010-3708"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2010-3708"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-3708"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2010-3862"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2010-3862"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-3862"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2010-3878"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2010-3878"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-3878"
    }
  ]
}