RHSA-2017:1409MediumCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform security update

Published
June 7, 2017
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2016-9606 — Resteasy: Yaml unmarshalling vulnerable to RCE CVE-2017-2595 — wildfly: Arbitrary file read via path traversal CVE-2017-2666 — undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests CVE-2017-2670 — undertow: IO thread DoS via unclean Websocket closing

🎯 Affected products1

  • Red Hat JBoss EAP 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Add authentication and authorization to any Resteasy endpoint which doesn't define a mime type, or defines a multipart mime type.

🔗 References (10)