RHSA-2020:1478HighCVSS 7.6
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
🎯 Affected products9
- Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Server
- Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el5.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server
- jbossweb-0:7.5.30-2.Final_redhat_2.1.ep6.el7.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 Server
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. The JBoss server process must be restarted for the update to take effect. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:1478
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/6.4/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806398
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1478.json