{"id":"RHSA-2009:1650","summary":"Red Hat Security Advisory: JBoss Enterprise Application Platform 4.2.0.CP08 update","modified":"2026-03-13T10:30:09.993011Z","published":"2024-09-29T16:26:34Z","upstream":["CVE-2009-0217","CVE-2009-1380","CVE-2009-2405","CVE-2009-2625","CVE-2009-3554"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2009:1650"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#moderate"},{"type":"ARTICLE","url":"http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=510023"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=511224"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=511915"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=512921"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=532111"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=539495"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2009/rhsa-2009_1650.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2009-0217"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2009-0217"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0217"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2009-1380"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2009-1380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1380"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2009-2405"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2009-2405"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2405"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2009-2625"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2009-2625"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2625"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2009-3554"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2009-3554"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3554"}],"affected":[{"package":{"name":"glassfish-jsf","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/glassfish-jsf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2_13-2.1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3-annotations","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3-annotations"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.3.1-1.11GA_CP02.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3-annotations-javadoc","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3-annotations-javadoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.3.1-1.11GA_CP02.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3-entitymanager","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3-entitymanager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.3.2-2.5.1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3-entitymanager-javadoc","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3-entitymanager-javadoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.3.2-2.5.1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"hibernate3-javadoc","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/hibernate3-javadoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jacorb","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jacorb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.3.0-1jpp.ep1.9.1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jboss-aop","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jboss-aop"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.5.5-3.CP04.2.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jboss-common","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jboss-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.1-0jpp.ep1.3.el5.1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jboss-remoting","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jboss-remoting"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.2.3-3.SP1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jboss-seam","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jboss-seam"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.1-1.ep1.14.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jboss-seam-docs","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jboss-seam-docs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.1-1.ep1.14.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jbossas","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jbossas"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.0-5.GA_CP08.5.2.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jbossas-4.2.0.GA_CP08-bin","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jbossas-4.2.0.GA_CP08-bin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.0-5.GA_CP08.5.2.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jbossas-client","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jbossas-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.0-5.GA_CP08.5.2.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jbossts","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jbossts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jbossweb","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jbossweb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.0.0-6.CP12.0jpp.ep1.2.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jcommon","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jcommon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0.16-1.1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jfreechart","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jfreechart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0.13-2.3.1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"jgroups","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/jgroups"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.7-1.ep1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"quartz","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/quartz"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.5.2-1jpp.patch01.ep1.4.1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"rh-eap-docs","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/rh-eap-docs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.0-6.GA_CP08.ep1.3.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"rh-eap-docs-examples","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/rh-eap-docs-examples"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.2.0-6.GA_CP08.ep1.3.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}},{"package":{"name":"xml-security","ecosystem":"Red Hat:jboss_enterprise_application_platform:4.2.0::el5","purl":"pkg:rpm/redhat/xml-security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.3.0-1.3.patch01.ep1.2.1.el5"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2009:1650.json"}}],"schema_version":"1.7.5"}