RHSA-2019:0380MediumCVSS 5.4

Red Hat Security Advisory: Red Hat Single Sign-On 7.2.6 security update

Published
February 19, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2018-10934 — wildfly-core: Cross-site scripting (XSS) in JBoss Management Console CVE-2018-14642 — undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents

🎯 Affected products1

  • Red Hat Single Sign-On 7.2.6 zip

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, and databases and database settings. The References section of this erratum contains a download link. You must log in to download the update.

🔗 References (8)