<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:zohocorp:manageengine_adaudit_plus:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3azohocorpmanageengine_adaudit_plus/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:15:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3azohocorpmanageengine_adaudit_plus/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in Red Hat Enterprise Linux Resteasy</title><link>https://feed.craftedsignal.io/briefs/2026-10-resteasy-info-disclosure/</link><pubDate>Thu, 08 Oct 2026 19:15:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-resteasy-info-disclosure/</guid><description>A vulnerability in the Resteasy component of Red Hat Enterprise Linux allows a remote, unauthenticated attacker to disclose sensitive information.</description><content:encoded><![CDATA[<p>A vulnerability has been identified in the Resteasy component included within Red Hat Enterprise Linux (RHEL). This security flaw, tracked as CVE-2024-5556, permits a remote and unauthenticated attacker to exploit improper request handling, potentially leading to the disclosure of sensitive system or application information. The vulnerability affects the way Resteasy processes specific HTTP requests, allowing unauthorized access to data that should otherwise be protected. This risk is particularly relevant for organizations hosting Java-based web services or applications on RHEL that utilize the Resteasy framework. Defensive teams should prioritize assessing the exposure of applications utilizing this component and monitor for unusual request patterns aimed at the Resteasy endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthorized party to gain access to sensitive information, which could facilitate further reconnaissance or compromise the confidentiality of the affected web service. This impacts any enterprise infrastructure relying on Red Hat Enterprise Linux hosting Resteasy-based applications.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Review RHEL security advisories for the specific patch version of Resteasy addressing CVE-2024-5556.</li>
<li>Audit web server logs for high volumes of malformed or unexpected HTTP requests targeting application endpoints known to utilize Resteasy.</li>
<li>Apply the latest security updates provided by Red Hat to all affected RHEL instances.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>information-disclosure</category><category>linux</category></item></channel></rss>