RHSA-2018:1251HighCVSS 8.6

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.2 security update

Published
April 25, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2018-1047 — undertow: Path traversal in ServletResourceManager class CVE-2018-1067 — undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) CVE-2018-8088 — slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution

🎯 Affected products1

  • Red Hat JBoss EAP 7.1

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect.

🔗 References (8)