RHSA-2019:4045HighCVSS 9.1

Red Hat Security Advisory: Red Hat Single Sign-On 7.3.5 security update

Published
December 2, 2019
Last Modified
August 15, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-9515 — HTTP/2: flood using SETTINGS frames results in unbounded memory growth CVE-2019-14837 — keycloak: keycloak uses hardcoded open dummy domain for new accounts enabling information disclosure CVE-2019-14838 — wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default CVE-2019-14843 — wildfly-security-manager: security manager authorization bypass

🎯 Affected products1

  • Red Hat Single Sign-On 7.3

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: It is not a very straight forward workaround but it is possible to mitigate this by manually editing the default Email ID ([email protected]) to some valid email ID ([email protected]) in the USER_ENTITY table in the RHSSO database used. Workaround: This flaw only affects the Security Manager running under JDK 11 or 8. To mitigate exposure to this flaw, do not run under those JDK versions.

🔗 References (12)