Third Party Index

Red Hat

redhat.com

FedRAMP Marketplace: Red Hat OpenShift Service on AWS (ROSA) Authorized High · 4 agency authorizations · since evidence

Transparency

Fair

Breakdown
Subprocessor listnot found0 / 30
Processing locationsno list0 / 8
Purposesno list0 / 7
Data processing addendum12 / 12
Trust center8 / 8
Privacy policy6 / 6
security.txt6 / 6
Security page5 / 5
Status page5 / 5
Vulnerability disclosurenot found0 / 5
Pages still reachable8 / 8
Total50 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

Red Hat transparency rating

For Red Hat's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/red-hat"><img src="https://thirdpartyindex.com/badge/red-hat.svg" alt="Red Hat transparency rating on Third Party Index" height="20"></a>
[![Red Hat transparency rating on Third Party Index](https://thirdpartyindex.com/badge/red-hat.svg)](https://thirdpartyindex.com/vendors/red-hat)

Documents

DocumentVerifiedChangedEvidence
Trust center snapshot
Data processing addendum snapshot
Privacy policy snapshot
Terms snapshot
Security page snapshot
security.txt snapshot
Status page statuspage snapshot

Subprocessors

None extracted.

Listed as a subprocessor by (6)

Purposes as each company states them.

Security record

What public security catalogs list for Red Hat, in their words.

Known exploited vulnerabilities

9 vulnerabilities in Red Hat's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2015-3246LibuserRed Hat Libuser Race Condition Vulnerability evidence
CVE-2015-5287Automatic Bug Reporting ToolRed Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability evidence
CVE-2018-14667JBoss RichFaces FrameworkRed Hat JBoss RichFaces Framework Expression Language Injection Vulnerability evidence
CVE-2021-3560PolkitRed Hat Polkit Incorrect Authorization Vulnerability evidence
CVE-2021-4034PolkitRed Hat Polkit Out-of-Bounds Read and Write Vulnerability used by ransomware evidence
CVE-2010-0738JBossRed Hat JBoss Authentication Bypass Vulnerability used by ransomware evidence
CVE-2010-1428JBossRed Hat JBoss Information Disclosure Vulnerability used by ransomware evidence
CVE-2010-1871JBoss Seam 2Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability evidence
CVE-2017-12149JBoss Application ServerRed Hat JBoss Application Server Remote Code Execution Vulnerability used by ransomware evidence

Source: CISA Known Exploited Vulnerabilities catalog.

Service status

minor Ongoing since : Support Cases - Post Upgrade Issues

minor Ongoing since : Automation Hub Upgrade

minor Ongoing since : Automation Hub Upgrade

major Ongoing since : OpenShift Cluster Manager Database Maintenance 2026-09-19

12 incidents in the last 52 days (8 major or critical, 4 minor, 0 with no stated impact) · typically resolved in 19 h 41 min · longest major: 36 days

BeganIncidentImpactLasted
Red Hat Connect Major Outage - Investigatingmajor21 min evidence
Support Cases - Post Upgrade Issuesminorongoing evidence
Automation Hub Upgrademinorongoing evidence
Automation Hub Upgrademinorongoing evidence
Support Customer Relationship Management (CRM) upgradecritical4 h 18 min evidence
Red Hat Partner Connect Maintenancemajor2 days evidence
Quay.io Security Scanning on maintenanceminor13 h 33 min evidence
catalog.redhat.com - Partial Outagemajor10 h 39 min evidence

As Red Hat's status page reports its own incidents (scheduled maintenance left out), read every few hours since .

Changes

None since tracking began.