RHSA-2018:2740HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.21 security update

Published
September 24, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2017-2582 — keycloak: SAML request parser replaces special strings with system properties CVE-2017-7536 — hibernate-validator: Privilege escalation when running under the security manager CVE-2018-1336 — tomcat: A bug in the UTF-8 decoder can lead to DoS CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 6.4

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (22)