Red Hat Security Advisory: Red Hat JBoss Fuse/A-MQ 6.3 R7 security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2016-8750 — karaf: LDAP injection in LDAPLoginModule CVE-2017-7559 — undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) CVE-2017-12165 — undertow: improper whitespace parsing leading to potential HTTP request smuggling CVE-2017-12626 — poi: Parsing of multiple file types can cause a denial of service via infinite loop or out of memory exception CVE-2017-1000487 — plexus-utils: Mishandled strings in Commandline class allow for command injection
🎯 Affected products2
- Red Hat JBoss A-MQ 6.3
- Red Hat JBoss Fuse 6.3
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are located in the download section of the customer portal. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2018:1322
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=securityPatches&version=6.3
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=jboss.amq.broker&version=6.3.0
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-fuse/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1481665
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1490301
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1524432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1532497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1539989
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_1322.json