[UPDATE] [hoch] Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Advanced Cluster Management ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Authentisierung zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Advanced Cluster Management enable remote denial of service attacks and authentication bypass.
- Who is affected
- Deployments running affected versions of Red Hat Enterprise Linux Advanced Cluster Management.
- Urgency
- High severity authentication bypass and denial of service vulnerabilities require urgent patching to prevent unauthorized access.
- Action
- Apply Red Hat security updates addressing CVE-2022-3517 and CVE-2022-41912 to affected Advanced Cluster Management installations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Enterprise Linux Advanced Cluster Management
Get an email when a new Enterprise Linux Advanced Cluster Management advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-2338
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-35171.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-419122.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2022-3517 | coverage & exploitation status | NVD · CVE.org |
| CVE-2022-41912 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] ILIAS: Mehrere Schwachstellen2026-09-08
- high[UPDATE] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-07
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen2026-09-07
- high[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen2026-09-07