RHSA-2017:2810HighCVSS 9.8

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform security update

Published
September 26, 2017
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2014-9970 — jasypt: Vulnerable to timing attack against the password hash comparison CVE-2015-6644 — bouncycastle: Information disclosure in GCMBlockCipher CVE-2017-2582 — keycloak: SAML request parser replaces special strings with system properties CVE-2017-5645 — log4j: Socket receiver deserialization vulnerability CVE-2017-7536 — hibernate-validator: Privilege escalation when running under the security manager CVE-2019-17571 — log4j: deserialization of untrusted data in SocketServer

🎯 Affected products1

  • Red Hat JBoss EAP 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Please note that the Log4j upstream strongly recommends against using the SerializedLayout with the SocketAppenders. Customers may mitigate this issue by removing the SocketServer class outright; or if they must continue to use SocketAppenders, they can modify their SocketAppender configuration from SerializedLayout to use JsonLayout instead. An example of this in log4j-server.properties might look like this: log4j.appender.file.layout=org.apache.log4j.JsonLayout

🔗 References (11)