RHSA-2018:1525HighCVSS 9.8

Red Hat Security Advisory: rhvm-appliance security and enhancement update

Published
May 15, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2017-12196 — undertow: Client can use bogus uri in Digest authentication CVE-2018-1073 — ovirt-engine: account enumeration through login to web console CVE-2018-1111 — dhcp: Command injection vulnerability in the DHCP client NetworkManager integration script CVE-2018-5968 — jackson-databind: unsafe deserialization due to incomplete blacklist (incomplete fix for CVE-2017-7525 and CVE-2017-17485) CVE-2018-7750 — python-paramiko: Authentication bypass in transport.py CVE-2018-8088 — slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution

🎯 Affected products6

  • Red Hat Virtualization 4 Hypervisor for RHEL 7
  • Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.2-20180504.0.el7.noarch as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.2-20180504.0.el7.noarch as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
  • rhvm-appliance-2:4.2-20180504.0.el7.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 7
  • rhvm-appliance-2:4.2-20180504.0.el7.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: Please access https://access.redhat.com/security/vulnerabilities/3442151 for information on how to mitigate this issue.

🔗 References (15)