Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2022:1539 - Security Advisory
Issued:
2022-04-26
Updated:
2022-04-26

RHSA-2022:1539 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: xmlrpc-c security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

XML-RPC is a remote procedure call (RPC) protocol that uses XML to encode its calls and HTTP as a transport mechanism. The xmlrpc-c packages provide a network protocol to allow a client program to make a simple RPC (remote procedure call) over the Internet. It converts an RPC into an XML document, sends it to a remote server using HTTP, and gets back the response in XML.

Security Fix(es):

  • expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2056366 - CVE-2022-25235 expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution

CVEs

  • CVE-2022-25235

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
xmlrpc-c-1.51.0-5.el8_1.1.src.rpm SHA-256: 9cff0c8716773a493cfbccc59971346fc4e8f9b0da6dff7db4a2b3ca2ba2d6f2
ppc64le
xmlrpc-c-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: db739c96568a367cd8018f1c49b4b5147def0fe53afcd5b011678d4400301930
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 11e3f5b5e0d836b323efe159f924bd1d3bdcc7e807cd449fdecb7bbea08337a4
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 39cd134d61cf774892b8493e064bce0cad387ab97e4b9021b08936654caf4ca2
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 4ec487cf70f4a7ec2f21780a457c1da4d846a2da91e1c06093812e23c63992de
xmlrpc-c-client-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 318b26b8f7366382b728f40136e664087036348c2026fade888b7217c46ed0c1
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: f7a342300d60e1777445187aef9c9b4eb35df5650a7e7876fe478eb53d5f7d1c
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 02466bbf1ede6effdcb7be06472a11ad0848e6cb8a7a5e418629dcf361cb2ea3
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.ppc64le.rpm SHA-256: 02017eac80ae4220a7533208d4c25fa4d411141bf28855722d38990f1a3a72f4

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
xmlrpc-c-1.51.0-5.el8_1.1.src.rpm SHA-256: 9cff0c8716773a493cfbccc59971346fc4e8f9b0da6dff7db4a2b3ca2ba2d6f2
x86_64
xmlrpc-c-1.51.0-5.el8_1.1.i686.rpm SHA-256: 3468e1e3f7c6736c86ff0c4ee5a7a635e4af453ed96dd6d25236b1b0292d95fc
xmlrpc-c-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: ad99e9e0c4859b142f3895dbf57986cefdceb2e75fe9f721a7a6a3b14942a015
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: a81494fad180d02c5d2081338106067b4bd12fd3e156f68fae1e82543f52465c
xmlrpc-c-apps-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 33c1290e68a16cdd5c6ca24dd94eca6e3fc21e2fc9897e14b3fb57689be30cd4
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: abb09c9a7a218d26a73b65f1cec7a04d7cacc28d011fcb07c1c0037507fbaa7a
xmlrpc-c-c++-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: f165855ff9d258f55a0fe7841a11cc7f632076bbae380e3c56549c60c1783560
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: c53512b657288414e75255da31f0aaa0451eb4f307cca56364ac9a1a53314dca
xmlrpc-c-client++-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: b1f0ad97dfa03b63b048e49f4de4b8d3ddcc6a891a9cca025f793cf3cfa869be
xmlrpc-c-client-1.51.0-5.el8_1.1.i686.rpm SHA-256: 2e601f4b02f63afcdf1394afb21d698631c63d5b4a824f5da7c26aa3a8281410
xmlrpc-c-client-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 52ed6d9416640362f0117b8ade78854703344e00752040c7c3c1d644431b378a
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: 83193f88200d411a7db11840bb987e3c8e3a3d4abc79b29096f321ef38d6bfbb
xmlrpc-c-client-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: c7f084d052e0c44f6dbbcf7feb6b592ab4c6ef5204412c8ae5b63ad0af5c33d4
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.i686.rpm SHA-256: 135738169d1dd76e86e7e06e9b384690d0860755ab2548a6d66f972809225574
xmlrpc-c-debuginfo-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: a83d6614741224ff772bca281d8dc6ce27dfc4b3d416ca2729006df83f2ab263
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.i686.rpm SHA-256: b0f1297f2dd3a78b416da8e34b45e1882b84816e9335b4a040749ae943eee395
xmlrpc-c-debugsource-1.51.0-5.el8_1.1.x86_64.rpm SHA-256: 1b0276a5362ec75844e89126090b63456eef4dd46928c859092e68b7fcb0dfc3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility