Red Hat
FedRAMP Marketplace: Red Hat OpenShift Service on AWS (ROSA) Authorized High · 4 agency authorizations · since evidence
No tracked subprocessors.
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center | snapshot | ||
| Data processing addendum | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot | ||
| Security page | snapshot | ||
| security.txt | snapshot | ||
| Status page statuspage | snapshot |
Subprocessors
None extracted.
Listed as a subprocessor by (6)
Purposes as each company states them.
Adobe adobe.com Adobe leverages OpenShift on top of its cloud infrastructure to orchestrate, scale, and manage its services. OpenShift is an implementation of Kubernetes, which enables container orchestration, scaling, and service management.
Deepgram deepgram.com A security-focused and scalable private registry platform for managing content across globally distributed datacenter and cloud environments.
Mailgun mailgun.com OS, Support
Microsoft microsoft.com Deploying, operating, and troubleshooting Azure Red Hat OpenShift
Sinch sinch.com OS, Support
TierPoint tierpoint.com Products & Services
Security record
What public security catalogs list for Red Hat, in their words.
Known exploited vulnerabilities
9 vulnerabilities in Red Hat's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2015-3246 | Libuser | Red Hat Libuser Race Condition Vulnerability | evidence |
| CVE-2015-5287 | Automatic Bug Reporting Tool | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | evidence |
| CVE-2018-14667 | JBoss RichFaces Framework | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | evidence |
| CVE-2021-3560 | Polkit | Red Hat Polkit Incorrect Authorization Vulnerability | evidence |
| CVE-2021-4034 | Polkit | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability used by ransomware | evidence |
| CVE-2010-0738 | JBoss | Red Hat JBoss Authentication Bypass Vulnerability used by ransomware | evidence |
| CVE-2010-1428 | JBoss | Red Hat JBoss Information Disclosure Vulnerability used by ransomware | evidence |
| CVE-2010-1871 | JBoss Seam 2 | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | evidence |
| CVE-2017-12149 | JBoss Application Server | Red Hat JBoss Application Server Remote Code Execution Vulnerability used by ransomware | evidence |
Service status
minor Ongoing since : Support Cases - Post Upgrade Issues
minor Ongoing since : Automation Hub Upgrade
minor Ongoing since : Automation Hub Upgrade
major Ongoing since : OpenShift Cluster Manager Database Maintenance 2026-09-19
12 incidents in the last 52 days (8 major or critical, 4 minor, 0 with no stated impact) · typically resolved in 19 h 41 min · longest major: 36 days
| Began | Incident | Impact | Lasted |
|---|---|---|---|
| Red Hat Connect Major Outage - Investigating | major | 21 min evidence | |
| Support Cases - Post Upgrade Issues | minor | ongoing evidence | |
| Automation Hub Upgrade | minor | ongoing evidence | |
| Automation Hub Upgrade | minor | ongoing evidence | |
| Support Customer Relationship Management (CRM) upgrade | critical | 4 h 18 min evidence | |
| Red Hat Partner Connect Maintenance | major | 2 days evidence | |
| Quay.io Security Scanning on maintenance | minor | 13 h 33 min evidence | |
| catalog.redhat.com - Partial Outage | major | 10 h 39 min evidence |
As Red Hat's status page reports its own incidents (scheduled maintenance left out), read every few hours since .
Changes
None since tracking began.