{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2024-41909",
        "tracking": {
            "current_release_date": "2026-07-10T19:23:55.166521Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2024-41909",
            "initial_release_date": "2024-08-12T17:02:54.899543Z",
            "revision_history": [
                {
                    "date": "2024-08-12T17:02:54.899543Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| Description created for source.| Unknown change.| References updated (1).| References created (1)."
                },
                {
                    "date": "2024-08-12T19:41:51.737723Z",
                    "number": "2",
                    "summary": "Source created.| Description created for source.| Products created (2).| References updated (2).| CWES updated (1)."
                },
                {
                    "date": "2024-08-12T20:39:18.889277Z",
                    "number": "3",
                    "summary": "Source created.| Description created for source.| CVSS created.| References created (7).| References updated (2).| CWES updated (1)."
                },
                {
                    "date": "2024-08-14T10:12:01.242023Z",
                    "number": "4",
                    "summary": "Source created.| EPSS created."
                },
                {
                    "date": "2024-08-16T18:27:29.294663Z",
                    "number": "5",
                    "summary": "Source created.| Description created for source.| CVSS created.| Products updated (8).| Products created (1).| References created (1).| References updated (3).| CWES updated (1)."
                },
                {
                    "date": "2024-08-31T05:00:06.216516Z",
                    "number": "6",
                    "summary": "CVSS created.| Unknown change.| Products created (1)."
                },
                {
                    "date": "2024-09-09T06:30:42.032346Z",
                    "number": "7",
                    "summary": "Source connected.| Description updated for source.| CVSS created.| References created (2).| References updated (12).| CWES updated (1)."
                },
                {
                    "date": "2024-10-07T14:35:57.549065Z",
                    "number": "8",
                    "summary": "References updated (1)."
                },
                {
                    "date": "2024-10-12T00:23:52.601807Z",
                    "number": "9",
                    "summary": "Source created.| Description created for source.| CVSS created.| Products updated (1)."
                },
                {
                    "date": "2024-10-16T00:28:20.885874Z",
                    "number": "10",
                    "summary": "Source connected.| Description updated for source.| CVSS created.| Products updated (1).| References updated (2)."
                },
                {
                    "date": "2024-10-16T03:41:31.269793Z",
                    "number": "11",
                    "summary": "Source connected.| Description updated for source."
                },
                {
                    "date": "2024-10-16T22:41:18.302278Z",
                    "number": "12",
                    "summary": "Source connected.| Description updated for source.| Products updated (5).| References updated (3)."
                },
                {
                    "date": "2024-10-18T20:50:57.413058Z",
                    "number": "13",
                    "summary": "Source connected.| EPSS created."
                },
                {
                    "date": "2024-12-05T01:25:22.335608Z",
                    "number": "14",
                    "summary": "Products updated (3).| References updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2024-12-26T10:42:57.220976Z",
                    "number": "15",
                    "summary": "Source created.| Description created for source."
                },
                {
                    "date": "2025-03-18T18:31:25.384916Z",
                    "number": "16",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2025-03-20T19:48:22.196351Z",
                    "number": "17",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2025-03-27T15:45:32.837853Z",
                    "number": "18",
                    "summary": "CVSS created.| Products created (1).| Products removed (2).| References created (1)."
                },
                {
                    "date": "2025-03-27T15:45:39.706760Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-03-27T16:26:47.408514Z",
                    "number": "20",
                    "summary": "Products created (1).| Product Identifiers created (1).| Products removed (1).| References updated (1).| CWES updated (1)."
                },
                {
                    "date": "2025-03-27T16:26:55.896137Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-03-29T20:02:56.920867Z",
                    "number": "22",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2025-03-30T20:24:01.078156Z",
                    "number": "23",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2025-06-30T21:56:19.322945Z",
                    "number": "24",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2025-06-30T21:56:21.860305Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-09-20T19:02:16.737819Z",
                    "number": "26",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2025-09-23T09:38:18.820521Z",
                    "number": "27",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (29).| References created (3)."
                },
                {
                    "date": "2025-09-23T09:38:24.366295Z",
                    "number": "28",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-10-03T01:32:16.330082Z",
                    "number": "29",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (12).| Product Identifiers created (15).| Products created (4).| References created (9).| CWES updated (1)."
                },
                {
                    "date": "2025-10-03T01:32:23.194307Z",
                    "number": "30",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-10-22T00:26:02.778294Z",
                    "number": "31",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| Product Remediations created (1).| References created (2)."
                },
                {
                    "date": "2025-10-22T00:26:05.706335Z",
                    "number": "32",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-10-22T11:08:05.541860Z",
                    "number": "33",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (6).| References created (3)."
                },
                {
                    "date": "2025-10-22T11:08:17.212840Z",
                    "number": "34",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-10-23T13:43:25.853823Z",
                    "number": "35",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2025-10-23T13:43:32.486371Z",
                    "number": "36",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2025-11-24T10:07:43.300041Z",
                    "number": "37",
                    "summary": "References created (1)."
                },
                {
                    "date": "2025-11-24T10:07:45.783551Z",
                    "number": "38",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-01-15T06:56:35.681953Z",
                    "number": "39",
                    "summary": "Manual regenerated (CSAFs rebuild product/vendor naming update)."
                },
                {
                    "date": "2026-03-19T13:31:51.478152Z",
                    "number": "40",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Identifiers created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T13:31:54.125704Z",
                    "number": "41",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T22:55:49.950571Z",
                    "number": "42",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-19T22:55:53.038331Z",
                    "number": "43",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T12:09:17.341544Z",
                    "number": "44",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-11T01:34:46.391705Z",
                    "number": "45",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-11T01:34:48.472799Z",
                    "number": "46",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-27T00:54:42.414125Z",
                    "number": "47",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-05-27T00:54:49.191390Z",
                    "number": "48",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-30T00:14:23.954354Z",
                    "number": "49",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-05-30T00:14:26.638685Z",
                    "number": "50",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-10T18:33:15.650216Z",
                    "number": "51",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-07-10T18:33:18.447448Z",
                    "number": "52",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-10T19:23:34.746666Z",
                    "number": "53",
                    "summary": "References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-07-10T19:23:47.321760Z",
                    "number": "54",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "54"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/unknown",
                                "product": {
                                    "name": "vers:netapp/unknown",
                                    "product_id": "CSAFPID-1239319"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Active IQ Unified Manager for Linux"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/unknown",
                                "product": {
                                    "name": "vers:netapp/unknown",
                                    "product_id": "CSAFPID-1209056"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Active IQ Unified Manager for Microsoft Windows"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/unknown",
                                "product": {
                                    "name": "vers:netapp/unknown",
                                    "product_id": "CSAFPID-1209057"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Active IQ Unified Manager for VMware vSphere"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/unknown",
                                "product": {
                                    "name": "vers:netapp/unknown",
                                    "product_id": "CSAFPID-1209059"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OnCommand Workflow Automation"
                    }
                ],
                "category": "vendor",
                "name": "NetApp"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<=2.11.0",
                                "product": {
                                    "name": "vers:semver/<=2.11.0",
                                    "product_id": "CSAFPID-2571344"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Apache MINA SSHD"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=2.11.0",
                                "product": {
                                    "name": "vers:unknown/<=2.11.0",
                                    "product_id": "CSAFPID-2571516",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:mina_sshd:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "MINA SSHD"
                    }
                ],
                "category": "vendor",
                "name": "Apache Software Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.2.1.4.0",
                                "product": {
                                    "name": "vers:unknown/12.2.1.4.0",
                                    "product_id": "CSAFPID-1549107",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:12.2.1.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/14.1.1.0.0",
                                "product": {
                                    "name": "vers:unknown/14.1.1.0.0",
                                    "product_id": "CSAFPID-1549109",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:14.1.1.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/14.1.2.0.0",
                                "product": {
                                    "name": "vers:unknown/14.1.2.0.0",
                                    "product_id": "CSAFPID-1847010",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:14.1.2.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/14.1.2.1.0",
                                "product": {
                                    "name": "vers:unknown/14.1.2.1.0",
                                    "product_id": "CSAFPID-5129879",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:14.1.2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.7",
                                "product": {
                                    "name": "vers:unknown/8.5.7",
                                    "product_id": "CSAFPID-1549108",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:8.5.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.5.8",
                                "product": {
                                    "name": "vers:unknown/8.5.8",
                                    "product_id": "CSAFPID-5129880",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:fusion_middleware:8.5.8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Fusion Middleware"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:oracle/12.2.1.4.0",
                                        "product": {
                                            "name": "vers:oracle/12.2.1.4.0",
                                            "product_id": "CSAFPID-1839883",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Middleware Common Libraries and Tools"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Fusion Middleware"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:oracle/19.0.0.10",
                                "product": {
                                    "name": "vers:oracle/19.0.0.10",
                                    "product_id": "CSAFPID-1173971",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0.0.10:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Oracle Retail Customer Management and Segmentation Foundation"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/19.0.0.10",
                                "product": {
                                    "name": "vers:unknown/19.0.0.10",
                                    "product_id": "CSAFPID-1177421",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:retail_applications:19.0.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/20.0.1",
                                "product": {
                                    "name": "vers:unknown/20.0.1",
                                    "product_id": "CSAFPID-1177424",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:retail_applications:20.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/21.0.0",
                                "product": {
                                    "name": "vers:unknown/21.0.0",
                                    "product_id": "CSAFPID-1177422",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:retail_applications:21.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.0.0",
                                "product": {
                                    "name": "vers:unknown/22.0.0",
                                    "product_id": "CSAFPID-1177425",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:retail_applications:22.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.0.0",
                                "product": {
                                    "name": "vers:unknown/23.0.0",
                                    "product_id": "CSAFPID-1177423",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:retail_applications:23.0.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Retail Applications"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7",
                                "product": {
                                    "name": "vers:unknown/7",
                                    "product_id": "CSAFPID-203546",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:jboss_enterprise_bpms_platform:7:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "JBoss Enterprise BRMS Platform"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8",
                                "product": {
                                    "name": "vers:unknown/8",
                                    "product_id": "CSAFPID-214721",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:jboss_enterprise_application_platform:8:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jboss Enterprise Application Platform"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2",
                                "product": {
                                    "name": "vers:unknown/2",
                                    "product_id": "CSAFPID-446428",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:a_mq_clients:2:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "a_mq_clients"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2",
                                "product": {
                                    "name": "vers:unknown/2",
                                    "product_id": "CSAFPID-203557",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:debezium:2:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "debezium"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/6",
                                "product": {
                                    "name": "vers:unknown/6",
                                    "product_id": "CSAFPID-983950",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:jboss_enterprise_web_server:6:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "jboss_enterprise_web_server"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-203045",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:ocp_tools:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "ocp_tools"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.11",
                                "product": {
                                    "name": "vers:unknown/3.11",
                                    "product_id": "CSAFPID-2434318",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:openshift:3.11:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "openshift"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7",
                                "product": {
                                    "name": "vers:unknown/7",
                                    "product_id": "CSAFPID-214053",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:redhat:red_hat_single_sign_on:7:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "red_hat_single_sign_on"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4",
                                "product": {
                                    "name": "vers:unknown/4",
                                    "product_id": "CSAFPID-1114349",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:redhat:rhev_hypervisor:4:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "rhev_hypervisor"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-4923361",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.10.0",
                                "product": {
                                    "name": "vers:unknown/2.10.0",
                                    "product_id": "CSAFPID-5002372",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.10.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.11.0",
                                "product": {
                                    "name": "vers:unknown/2.11.0",
                                    "product_id": "CSAFPID-5002373",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.11.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0",
                                "product": {
                                    "name": "vers:unknown/2.2.0",
                                    "product_id": "CSAFPID-4923362",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.2.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.3.0",
                                "product": {
                                    "name": "vers:unknown/2.3.0",
                                    "product_id": "CSAFPID-4923363",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.3.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.4.0",
                                "product": {
                                    "name": "vers:unknown/2.4.0",
                                    "product_id": "CSAFPID-4923364",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.4.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.0",
                                "product": {
                                    "name": "vers:unknown/2.5.0",
                                    "product_id": "CSAFPID-4923365",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.5.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.5.1",
                                "product": {
                                    "name": "vers:unknown/2.5.1",
                                    "product_id": "CSAFPID-4923366",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.6.0",
                                "product": {
                                    "name": "vers:unknown/2.6.0",
                                    "product_id": "CSAFPID-4923367",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.6.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.7.0",
                                "product": {
                                    "name": "vers:unknown/2.7.0",
                                    "product_id": "CSAFPID-4923368",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.7.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.8.0",
                                "product": {
                                    "name": "vers:unknown/2.8.0",
                                    "product_id": "CSAFPID-4923369",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.0",
                                "product": {
                                    "name": "vers:unknown/2.9.0",
                                    "product_id": "CSAFPID-4923370",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.9.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.1",
                                "product": {
                                    "name": "vers:unknown/2.9.1",
                                    "product_id": "CSAFPID-4923371",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.9.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.2",
                                "product": {
                                    "name": "vers:unknown/2.9.2",
                                    "product_id": "CSAFPID-4923372",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.9.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.9.3",
                                "product": {
                                    "name": "vers:unknown/2.9.3",
                                    "product_id": "CSAFPID-5002374",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.sshd/sshd-common@2.9.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<2.12.0",
                                "product": {
                                    "name": "vers:unknown/>=0|<2.12.0",
                                    "product_id": "CSAFPID-5002375"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.10.0",
                                "product": {
                                    "name": "vers:unknown/sshd-0.10.0",
                                    "product_id": "CSAFPID-3895128"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.10.1",
                                "product": {
                                    "name": "vers:unknown/sshd-0.10.1",
                                    "product_id": "CSAFPID-3895129"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.11.0",
                                "product": {
                                    "name": "vers:unknown/sshd-0.11.0",
                                    "product_id": "CSAFPID-3895130"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.12.0",
                                "product": {
                                    "name": "vers:unknown/sshd-0.12.0",
                                    "product_id": "CSAFPID-3895131"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.13.0",
                                "product": {
                                    "name": "vers:unknown/sshd-0.13.0",
                                    "product_id": "CSAFPID-3895132"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-0.9.0",
                                "product": {
                                    "name": "vers:unknown/sshd-0.9.0",
                                    "product_id": "CSAFPID-3895133"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.0.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.0.0",
                                    "product_id": "CSAFPID-3895134"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.1.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.1.0",
                                    "product_id": "CSAFPID-3895135"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.2.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.2.0",
                                    "product_id": "CSAFPID-3895136"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.3.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.3.0",
                                    "product_id": "CSAFPID-3895137"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.4.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.4.0",
                                    "product_id": "CSAFPID-3895138"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.5.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.5.0",
                                    "product_id": "CSAFPID-3895139"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.6.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.6.0",
                                    "product_id": "CSAFPID-3895140"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-1.7.0",
                                "product": {
                                    "name": "vers:unknown/sshd-1.7.0",
                                    "product_id": "CSAFPID-3895141"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.0.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.0.0",
                                    "product_id": "CSAFPID-3895142"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.1.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.1.0",
                                    "product_id": "CSAFPID-3895143"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.10.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.10.0",
                                    "product_id": "CSAFPID-3895144"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.11.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.11.0",
                                    "product_id": "CSAFPID-3895145"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.2.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.2.0",
                                    "product_id": "CSAFPID-3895146"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.3.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.3.0",
                                    "product_id": "CSAFPID-3895147"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.4.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.4.0",
                                    "product_id": "CSAFPID-3895148"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.5.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.5.0",
                                    "product_id": "CSAFPID-3895149"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.5.1",
                                "product": {
                                    "name": "vers:unknown/sshd-2.5.1",
                                    "product_id": "CSAFPID-3895150"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.6.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.6.0",
                                    "product_id": "CSAFPID-3895151"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.7.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.7.0",
                                    "product_id": "CSAFPID-3895152"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.8.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.8.0",
                                    "product_id": "CSAFPID-3895153"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.9.0",
                                "product": {
                                    "name": "vers:unknown/sshd-2.9.0",
                                    "product_id": "CSAFPID-3895154"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.9.1",
                                "product": {
                                    "name": "vers:unknown/sshd-2.9.1",
                                    "product_id": "CSAFPID-3895155"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/sshd-2.9.2",
                                "product": {
                                    "name": "vers:unknown/sshd-2.9.2",
                                    "product_id": "CSAFPID-3895156"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "mina-sshd"
                    }
                ],
                "category": "vendor",
                "name": "Apache"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2024-41909",
            "cwe": {
                "id": "CWE-354",
                "name": "Improper Validation of Integrity Check Value"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2024-41909"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2024-41909"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "github - https://github.com/advisories/GHSA-2326-hx7g-3m9r"
                },
                {
                    "category": "description",
                    "text": "mina-sshd: integrity check bypass vulnerability",
                    "title": "redhat - https://bugzilla.redhat.com/show_bug.cgi?id=2304442"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Apache MINA SSHD. This flaw allows an attacker who can intercept traffic between the client and server to drop certain packets from the stream. This potentially causes a Terrapin attack where the client and server consequently end up with a connection for which some security features have been downgraded or disabled.",
                    "title": "redhat - https://access.redhat.com/errata/RHSA-2024:1194"
                },
                {
                    "category": "description",
                    "text": "Multiple NetApp products incorporate Apache MINA SSHD. Apache MINA SSHD versions through 2.11.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.",
                    "title": "netapp - https://security.netapp.com/advisory/ntap-20241011-0006/"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (Apache Mina SSHD)).   The supported version that is affected is 19.0.0.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "oracle - https://www.oracle.com/docs/tech/security-alerts/cpuoct2024csaf.json"
                },
                {
                    "category": "description",
                    "text": "Multiple vulnerabilities were identified in Oracle Products, a remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.",
                    "title": "hkcert - https://www.hkcert.org/security-bulletin/oracle-products-multiple-vulnerabilities_20241016"
                },
                {
                    "category": "description",
                    "text": "In Oracle Retail Applications existieren mehrere Schwachstellen. Durch Ausnutzung dieser Schwachstellen kann ein entfernter, anonymer Angreifer die Integrität und Verfügbarkeit gefährden. Für die Ausnutzung einiger dieser Schwachstellen ist keine Benutzerinteraktion notwendig. Oracle veröffentlicht keine weiteren Details zu diesen Schwachstellen (außer der Information in der Risiko Matrix im Oracle Advisory zum Critical Patch Update, siehe Link unten in diesem Advisory). Aufgrund der knappen Informationslage erfolgt die Bewertung der Schadenshöhe ausschließlich auf Basis der CVSS Impact Matrix. Der Maximalwert für diese Produkte ist \"HIGH\" für \"Integrity\" und \"Availability\" über alle Schwachstellen aggregiert und bewirkt damit eine Bewertung mit dem Wert \"MITTEL\" für die Schadenshöhe.",
                    "title": "certbundde - https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3221.json"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which  some security features have been downgraded or disabled, aka a Terrapin  attack  The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2024-41909"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2024-41909.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-2326-hx7g-3m9r.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina SSHD)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "oracle - https://www.oracle.com/docs/tech/security-alerts/cpuoct2025csaf.json"
                },
                {
                    "category": "description",
                    "text": "Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which \nsome security features have been downgraded or disabled, aka a Terrapin \nattack\n\nThe mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-41909"
                },
                {
                    "category": "other",
                    "text": "0.00581",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.2",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, VENDOR FIX as product remediation category, There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Apache, There is cwe data available from source Github, Is related to a product by vendor Red Hat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-446428",
                    "CSAFPID-203045",
                    "CSAFPID-203557",
                    "CSAFPID-214721",
                    "CSAFPID-983950",
                    "CSAFPID-2434318",
                    "CSAFPID-203546",
                    "CSAFPID-214053",
                    "CSAFPID-1114349",
                    "CSAFPID-1173971",
                    "CSAFPID-1177421",
                    "CSAFPID-1177422",
                    "CSAFPID-1177423",
                    "CSAFPID-1177424",
                    "CSAFPID-1177425",
                    "CSAFPID-1209056",
                    "CSAFPID-1209057",
                    "CSAFPID-1209059",
                    "CSAFPID-1239319",
                    "CSAFPID-2571344",
                    "CSAFPID-2571516",
                    "CSAFPID-3895128",
                    "CSAFPID-3895129",
                    "CSAFPID-3895130",
                    "CSAFPID-3895131",
                    "CSAFPID-3895132",
                    "CSAFPID-3895133",
                    "CSAFPID-3895134",
                    "CSAFPID-3895135",
                    "CSAFPID-3895136",
                    "CSAFPID-3895137",
                    "CSAFPID-3895138",
                    "CSAFPID-3895139",
                    "CSAFPID-3895140",
                    "CSAFPID-3895141",
                    "CSAFPID-3895142",
                    "CSAFPID-3895143",
                    "CSAFPID-3895144",
                    "CSAFPID-3895145",
                    "CSAFPID-3895146",
                    "CSAFPID-3895147",
                    "CSAFPID-3895148",
                    "CSAFPID-3895149",
                    "CSAFPID-3895150",
                    "CSAFPID-3895151",
                    "CSAFPID-3895152",
                    "CSAFPID-3895153",
                    "CSAFPID-3895154",
                    "CSAFPID-3895155",
                    "CSAFPID-3895156",
                    "CSAFPID-4923361",
                    "CSAFPID-4923362",
                    "CSAFPID-4923363",
                    "CSAFPID-4923364",
                    "CSAFPID-4923365",
                    "CSAFPID-4923366",
                    "CSAFPID-4923367",
                    "CSAFPID-4923368",
                    "CSAFPID-4923369",
                    "CSAFPID-4923370",
                    "CSAFPID-4923371",
                    "CSAFPID-4923372",
                    "CSAFPID-5002372",
                    "CSAFPID-5002373",
                    "CSAFPID-5002374",
                    "CSAFPID-5002375",
                    "CSAFPID-1839883",
                    "CSAFPID-1549107",
                    "CSAFPID-1549108",
                    "CSAFPID-1549109",
                    "CSAFPID-1847010",
                    "CSAFPID-5129879",
                    "CSAFPID-5129880"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/41xxx/CVE-2024-41909.json"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-2326-hx7g-3m9r"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304442"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2024:1194"
                },
                {
                    "category": "external",
                    "summary": "Source - netapp",
                    "url": "https://security.netapp.com/advisory/ntap-20241011-0006/"
                },
                {
                    "category": "external",
                    "summary": "Source - oracle",
                    "url": "https://www.oracle.com/docs/tech/security-alerts/cpuoct2024csaf.json"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/oracle-products-multiple-vulnerabilities_20241016"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3221.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2024-41909.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-2326-hx7g-3m9r.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - oracle",
                    "url": "https://www.oracle.com/docs/tech/security-alerts/cpuoct2025csaf.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2359.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2025-0334"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscinternal",
                    "url": "https://www.ncsc.nl/internal/CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=60000"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=70000"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=80000"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=90000"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/apache/mina-sshd/issues/445"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; netapp; nvd; osv; redhat",
                    "url": "https://lists.apache.org/thread/vwf1ot8wx1njyy8n19j5j2tcnjnozt3b"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/apache/mina-sshd/pull/449"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/apache/mina-sshd/commit/315739e4e9d1dc7a4ff32ea64936982ed0b73e76"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/apache/mina-sshd/commit/6b0fd46f64bcb75eeeee31d65f10242660aad7c1"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/apache/mina-sshd/commit/7b2c781640a7a78a9455b86593a1f63c9e8cab92"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/apache/mina-sshd"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://github.com/apache/mina-sshd/releases/tag/sshd-2.12.0"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2024-41909"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2304442"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2024:1194"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/#moderate"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2238614"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2240036"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254594"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_1194.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1194.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - hkcert; oracle",
                    "url": "https://www.oracle.com/security-alerts/cpuoct2024.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - oracle",
                    "url": "https://www.oracle.com/docs/tech/security-alerts/cpuoct2024csaf.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3221.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3221"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.oracle.com/security-alerts/cpuoct2024.html#AppendixRAPP"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://security.netapp.com/advisory/ntap-20241011-0006/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://security.netapp.com/advisory/ntap-20241011-0006"
                },
                {
                    "category": "external",
                    "summary": "Reference - oracle",
                    "url": "https://www.oracle.com/security-alerts/cpuoct2025.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - oracle",
                    "url": "https://www.oracle.com/docs/tech/security-alerts/cpuoct2025csaf.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2359.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2359"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixFMW"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.cisa.gov/news-events/alerts/2025/11/21/cisa-adds-one-known-exploited-vulnerability-catalog"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41909.json"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "CSAFPID-1173971"
                    ],
                    "url": "https://support.oracle.com/rs?type=doc&amp;id=3046279.1"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "CSAFPID-1839883"
                    ],
                    "url": "https://support.oracle.com/rs?type=doc&amp;id=3105435.1"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1114349",
                        "CSAFPID-1173971",
                        "CSAFPID-1177421",
                        "CSAFPID-1177422",
                        "CSAFPID-1177423",
                        "CSAFPID-1177424",
                        "CSAFPID-1177425",
                        "CSAFPID-1209056",
                        "CSAFPID-1209057",
                        "CSAFPID-1209059",
                        "CSAFPID-1239319",
                        "CSAFPID-1549107",
                        "CSAFPID-1549108",
                        "CSAFPID-1549109",
                        "CSAFPID-1839883",
                        "CSAFPID-1847010",
                        "CSAFPID-203045",
                        "CSAFPID-203546",
                        "CSAFPID-203557",
                        "CSAFPID-214053",
                        "CSAFPID-214721",
                        "CSAFPID-2434318",
                        "CSAFPID-2571344",
                        "CSAFPID-2571516",
                        "CSAFPID-3895128",
                        "CSAFPID-3895129",
                        "CSAFPID-3895130",
                        "CSAFPID-3895131",
                        "CSAFPID-3895132",
                        "CSAFPID-3895133",
                        "CSAFPID-3895134",
                        "CSAFPID-3895135",
                        "CSAFPID-3895136",
                        "CSAFPID-3895137",
                        "CSAFPID-3895138",
                        "CSAFPID-3895139",
                        "CSAFPID-3895140",
                        "CSAFPID-3895141",
                        "CSAFPID-3895142",
                        "CSAFPID-3895143",
                        "CSAFPID-3895144",
                        "CSAFPID-3895145",
                        "CSAFPID-3895146",
                        "CSAFPID-3895147",
                        "CSAFPID-3895148",
                        "CSAFPID-3895149",
                        "CSAFPID-3895150",
                        "CSAFPID-3895151",
                        "CSAFPID-3895152",
                        "CSAFPID-3895153",
                        "CSAFPID-3895154",
                        "CSAFPID-3895155",
                        "CSAFPID-3895156",
                        "CSAFPID-446428",
                        "CSAFPID-4923361",
                        "CSAFPID-4923362",
                        "CSAFPID-4923363",
                        "CSAFPID-4923364",
                        "CSAFPID-4923365",
                        "CSAFPID-4923366",
                        "CSAFPID-4923367",
                        "CSAFPID-4923368",
                        "CSAFPID-4923369",
                        "CSAFPID-4923370",
                        "CSAFPID-4923371",
                        "CSAFPID-4923372",
                        "CSAFPID-5002372",
                        "CSAFPID-5002373",
                        "CSAFPID-5002374",
                        "CSAFPID-5002375",
                        "CSAFPID-5129879",
                        "CSAFPID-5129880",
                        "CSAFPID-983950"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "details": "Successful exploitation of this vulnerability could lead to addition or modification of data.",
                    "product_ids": [
                        "CSAFPID-1209056",
                        "CSAFPID-1209057",
                        "CSAFPID-1209059",
                        "CSAFPID-1239319"
                    ]
                }
            ],
            "title": "CVE-2024-41909"
        }
    ]
}