RHEA-2019:1119MediumCVSS 5.3
Red Hat Enhancement Advisory: rhvm-appliance security, bug fix, and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2018-14642 — undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents
🎯 Affected products6
- Red Hat Virtualization 4 Hypervisor for RHEL 7
- Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.3-20190502.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.3-20190502.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.3-20190502.0.el7.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
- rhvm-appliance-2:4.3-20190502.0.el7.x86_64 as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2974891