RHSA-2019:2937HighCVSS 9.8

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 8 security update

Published
October 1, 2019
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2019-10184 — undertow: Information leak in requests for directories without trailing slashes CVE-2019-10202 — codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities CVE-2019-10212 — undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files CVE-2019-12086 — jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. CVE-2019-12384 — jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution CVE-2019-12814 — jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. CVE-2019-14379 — jackson-databind: default typing mishandling leading to remote code execution

🎯 Affected products164

  • Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-0:2.9.0-1.redhat_00005.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-cli-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-commons-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-core-client-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-dto-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-hornetq-protocol-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-hqclient-protocol-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jdbc-store-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jms-client-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jms-server-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-journal-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-ra-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-selector-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-server-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-service-extensions-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-tools-0:2.9.0-1.redhat_00005.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-0:1.9.13-9.redhat_00006.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-core-asl-0:1.9.13-9.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-jaxrs-0:1.9.13-9.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-mapper-asl-0:1.9.13-9.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-xc-0:1.9.13-9.redhat_00006.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-glassfish-jsf-0:2.3.5-4.SP3_redhat_00002.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-glassfish-jsf-0:2.3.5-4.SP3_redhat_00002.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-hal-console-0:3.0.16-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-hal-console-0:3.0.16-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-hibernate-0:5.3.11-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-hibernate-0:5.3.11-2.SP1_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • +134 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: Use Elytron instead of legacy Security subsystem. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` Workaround: This vulnerability relies on jdom (org.jdom) or jdom2 (org.jdom2) being present in the application's ClassPath. Applications using jackson-databind that do not also use jdom or jdom2 are not impacted by this vulnerability. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`

🔗 References (39)