Red Hat Security Advisory: Red Hat JBoss Web Server 5.3 release
🔗 CVE IDs covered (5)
📋 Description
CVE-2019-12418 — tomcat: local privilege escalation CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2019-17569 — tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-1935 — tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
🎯 Affected products1
- Red Hat JBoss Web Server (JWS) 5.3
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Disable JMX Remote if monitoring is only needed locally and there is no need to monitor Tomcat remotely. If JMX Remote is required and cannot be disabled, then use the built-in remote JMX facilities provided by the JVM. Please note that JMX Remote Lifecycle Listener is now deprecated and may be removed from both Tomcat 7 [1] and Tomcat 9 [2] after 2020-12-31. [1] https://tomcat.apache.org/tomcat-7.0-doc/config/listeners.html#Deprecated_Implementations [2] https://tomcat.apache.org/tomcat-9.0-doc/config/listeners.html#Deprecated_Implementations Workaround: Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite. For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:1521
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785699
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806398
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806849
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1521.json