RHSA-2018:2425HighCVSS 7.6

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1 security update

Published
August 15, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2017-12624 — cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services CVE-2018-8039 — apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service CVE-2018-10862 — wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (Zip Slip) CVE-2018-1000180 — bouncycastle: flaw in the low-level interface to RSA key pair generator

🎯 Affected products1

  • Red Hat JBoss EAP 7.1

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect.

🔗 References (11)