RHEA-2019:1119MediumCVSS 5.3

Red Hat Enhancement Advisory: rhvm-appliance security, bug fix, and enhancement update

Published
May 8, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2018-14642 — undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents

🎯 Affected products6

  • Red Hat Virtualization 4 Hypervisor for RHEL 7
  • Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.3-20190502.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.3-20190502.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.3-20190502.0.el7.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.3-20190502.0.el7.x86_64 as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2974891

🔗 References (3)