RHSA-2019:1162MediumCVSS 5.4

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.22 security update

Published
May 13, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2018-8034 — tomcat: Host name verification missing in WebSocket client CVE-2018-10934 — wildfly-core: Cross-site scripting (XSS) in JBoss Management Console CVE-2018-1000632 — dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 6.4

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update).

🔗 References (15)