Red Hat released JBoss Enterprise Application Platform (EAP) 7.4.4 for Red Hat Enterprise Linux 7, replacing EAP 7.4.3 and updating org.apache.logging.log4j from version 2.14.0.redhat-00002 to 2.17.1.redhat-00001. The security update addresses seven Apache Log4j and Log4j Core vulnerabilities: CVE-2021-4104, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105, CVE-2022-23302, CVE-2022-23305, and CVE-2022-23307; several have conditionally exploitable remote-code-execution impact.
The EAP 7.4.z maintenance work also included an upgrade of Hibernate ORM from 5.3.24.Final-redhat-00001 to 5.3.25.Final-redhat-00002. Red Hat advised customers to back up existing EAP installations and deployed applications before applying the RHSA-2022:1296 update.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Unity Linux published advisory UTSA-2026-031579 for jboss-logging packages on Unity Linux 20.1050e, 20.1060e, 20.1070-8ae, and 20.1070e. The update remediates CVE-2021-45105, a Log4j2 uncontrolled-recursion flaw that can cause denial of service when an attacker controls Thread Context Map data.
Unity Linux published advisory UTSA-2026-031578 for jboss-logging packages on Unity Linux 20.1050e, 20.1060e, 20.1070-8ae, and 20.1070e. The update remediates CVE-2021-45046, the incomplete Log4Shell mitigation that can enable information disclosure and code execution in certain logging configurations.
Unity Linux published advisory UTSA-2026-030642 for affected wildfly-security-manager packages on Unity Linux 20 releases, remediating CVE-2021-45046. The update addresses the incomplete Log4Shell fix that can permit information disclosure or code execution in certain logging configurations.
Red Hat issued low-severity advisory RHSA-2022:1296 for JBoss Enterprise Application Platform 7.4 on RHEL 7. The update replaced EAP 7.4.3 with 7.4.4, upgraded Log4j to 2.17.1, and remediated seven Log4j/Log4j Core vulnerabilities, including conditionally exploitable remote-code-execution flaws.
Red Hat closed its tracking bug for CVE-2022-23305, an SQL-injection issue affecting Log4j 1.2.x deployments explicitly configured with JDBCAppender. Attackers able to control logged application input or HTTP headers could manipulate the configured SQL statement through crafted log messages.
Red Hat issued RHSA-2021:5094 for OpenShift Container Platform 3.11.z, providing updated packages and images that remediate Log4Shell (CVE-2021-44228) in log4j-core. The advisory also referenced CVE-2021-45046 and instructed administrators to upgrade clusters through the asynchronous errata update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceissues.redhat.com
Open sourceissues.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.