Security is at the top of mind for our customers, and understanding the language and practices around security is vital for teams delivering applications and managing infrastructure. Understanding how Red Hat reports and evaluates security vulnerabilities — as well as the tools Red Hat uses to communicate and address vulnerabilities — goes a long way towards protecting your IT environment.
In addition, learning why Red Hat utilizes an open methodology to vulnerability management is equally important. Red Hat doesn’t just produce enterprise open source software; from start to finish we do so with transparency and accountability. We believe this is critical for customers and communities to fully understand the vulnerabilities that may impact them, as well as provide the data necessary to make appropriate, informed decisions.
You'll find a great deal of information on vulnerabilities that affect open source software that makes up Red Hat's products, but what we provide often differs from the upstream software. Since vulnerability analysis on upstream software may not apply to the products you use today, we provide authoritative information about our products that can help inform your practices and response.
We communicate about our policies and practices frequently, through posts on the Red Hat Blog, through advisories and in articles on the Red Hat Customer Portal, sessions at Red Hat Summit and more.
Bringing it all together
We'll continue to write and speak about these topics, but we wanted to give our customers and communities a single document as a convenient reference to better understand how we categorize, address and respond to security vulnerabilities.
In "An Open Approach to Vulnerability Management" you can learn:
-
How Red Hat reports and evaluates vulnerabilities using Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), and the Common Vulnerability Scoring System (CVSS) standards.
-
How our Severity Ratings system works and when a vulnerability poses a severe and immediate threat to your environment and when a vulnerability is unlikely to impact your environment.
-
How Red Hat's product support life cycle informs our response to security issues.
-
How Red Hat uses backporting and rebasing to address vulnerabilities.
-
What content signing is, and how to use it to verify software is from Red Hat, and untampered with.
Grab An Open Approach to Vulnerability Management today
There's plenty more to learn about Red Hat’s methodology of understanding and addressing security vulnerabilities. Get your copy of An Open Approach to Vulnerability Managements today and be sure to follow the Security channel here on the Red Hat Blog.
Über den Autor
Red Hat Product Security provides the guidance, stability and security needed to confidently deploy enterprise solutions.
Nach Thema durchsuchen
Automatisierung
Das Neueste zum Thema IT-Automatisierung für Technologien, Teams und Umgebungen
Künstliche Intelligenz
Erfahren Sie das Neueste von den Plattformen, die es Kunden ermöglichen, KI-Workloads beliebig auszuführen
Open Hybrid Cloud
Erfahren Sie, wie wir eine flexiblere Zukunft mit Hybrid Clouds schaffen.
Sicherheit
Erfahren Sie, wie wir Risiken in verschiedenen Umgebungen und Technologien reduzieren
Edge Computing
Erfahren Sie das Neueste von den Plattformen, die die Operations am Edge vereinfachen
Infrastruktur
Erfahren Sie das Neueste von der weltweit führenden Linux-Plattform für Unternehmen
Anwendungen
Entdecken Sie unsere Lösungen für komplexe Herausforderungen bei Anwendungen
Original Shows
Interessantes von den Experten, die die Technologien in Unternehmen mitgestalten
Produkte
- Red Hat Enterprise Linux
- Red Hat OpenShift
- Red Hat Ansible Automation Platform
- Cloud-Services
- Alle Produkte anzeigen
Tools
- Training & Zertifizierung
- Eigenes Konto
- Kundensupport
- Für Entwickler
- Partner finden
- Red Hat Ecosystem Catalog
- Mehrwert von Red Hat berechnen
- Dokumentation
Testen, kaufen und verkaufen
Kommunizieren
Über Red Hat
Als weltweit größter Anbieter von Open-Source-Software-Lösungen für Unternehmen stellen wir Linux-, Cloud-, Container- und Kubernetes-Technologien bereit. Wir bieten robuste Lösungen, die es Unternehmen erleichtern, plattform- und umgebungsübergreifend zu arbeiten – vom Rechenzentrum bis zum Netzwerkrand.
Wählen Sie eine Sprache
Red Hat legal and privacy links
- Über Red Hat
- Jobs bei Red Hat
- Veranstaltungen
- Standorte
- Red Hat kontaktieren
- Red Hat Blog
- Diversität, Gleichberechtigung und Inklusion
- Cool Stuff Store
- Red Hat Summit