RHSA-2018:2743HighCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.21 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2017-2582 — keycloak: SAML request parser replaces special strings with system properties CVE-2017-7536 — hibernate-validator: Privilege escalation when running under the security manager CVE-2018-1336 — tomcat: A bug in the UTF-8 decoder can lead to DoS CVE-2018-10237 — guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
🎯 Affected products166
- Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-0:1.9.9-14.redhat_7.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-0:1.9.9-14.redhat_7.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-core-asl-0:1.9.9-14.redhat_7.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-jaxrs-0:1.9.9-14.redhat_7.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-mapper-asl-0:1.9.9-14.redhat_7.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- codehaus-jackson-xc-0:1.9.9-14.redhat_7.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- guava-libraries-0:13.0.1-5.redhat_3.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- guava-libraries-0:13.0.1-5.redhat_3.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- hibernate4-validator-0:4.3.4-1.Final_redhat_1.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- hibernate4-validator-0:4.3.4-1.Final_redhat_1.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- hornetq-0:2.3.25-27.SP28_redhat_1.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- hornetq-0:2.3.25-27.SP28_redhat_1.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-common-api-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-common-impl-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-common-spi-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-core-api-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-core-impl-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-deployers-common-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-jdbc-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-spec-api-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- ironjacamar-validator-eap6-0:1.0.42-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-appclient-0:7.5.21-1.Final_redhat_1.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-appclient-0:7.5.21-1.Final_redhat_1.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-cli-0:7.5.21-1.Final_redhat_1.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-cli-0:7.5.21-1.Final_redhat_1.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-client-all-0:7.5.21-1.Final_redhat_1.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-as-client-all-0:7.5.21-1.Final_redhat_1.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- +136 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2018:2743
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-US/JBoss_Enterprise_Application_Platform/6.4/index.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1261190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1410481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1465573
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1570200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1578830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1580440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1594389
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1602226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1606334
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1607591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1610355
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1610742
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1611770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1614448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1615347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1615380
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2743.json