Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_build_of_apache_camel_for_spring_boot_3:apache-santuario apache-santuario as a component of Red Hat build of Apache Camel for Spring Boot 3 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_data_grid_8:apache-santuario apache-santuario as a component of Red Hat Data Grid 8 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_fuse_7:apache-santuario apache-santuario as a component of Red Hat Fuse 7 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_integration_camel_k_1:apache-santuario apache-santuario as a component of Red Hat Integration Camel K 1 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_integration_camel_quarkus_1:apache-santuario apache-santuario as a component of Red Hat Integration Camel Quarkus 1 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_jboss_data_grid_7:apache-santuario apache-santuario as a component of Red Hat JBoss Data Grid 7 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_jboss_data_virtualization_6:apache-santuario apache-santuario as a component of Red Hat JBoss Data Virtualization 6 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_jboss_fuse_6:apache-santuario apache-santuario as a component of Red Hat JBoss Fuse 6 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_jboss_fuse_service_works_6:apache-santuario apache-santuario as a component of Red Hat JBoss Fuse Service Works 6 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| red_hat_single_sign-on_7:apache-santuario apache-santuario as a component of Red Hat Single Sign-On 7 | not affected vulnerable code not present | no version stated vendor label: apache-santuario | not applicable | csaf_redhat | |
| logging_subsystem_for_red_hat_openshift:elasticsearch6-container elasticsearch6-container as a component of Logging Subsystem for Red Hat OpenShift | not affected vulnerable code not present | no version stated vendor label: elasticsearch6-container | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:xmlsec xmlsec as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: xmlsec | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_7:xmlsec xmlsec as a component of Red Hat JBoss Enterprise Application Platform 7 | not affected vulnerable code not present | no version stated vendor label: xmlsec | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_expansion_pack:xmlsec xmlsec as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack | not affected vulnerable code not present | no version stated vendor label: xmlsec | not applicable | csaf_redhat | |
| n/a/n/a n/a · n/a | affected | no version stated vendor label: all versions | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.