RHSA-2020:2059HighCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 on RHEL 7 security update

Published
May 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1732 — Soteria: security identity corruption across concurrent threads CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size

🎯 Affected products200

  • Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el7eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-cli-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-commons-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-core-client-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-dto-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-hornetq-protocol-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-hqclient-protocol-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-jdbc-store-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-jms-client-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-jms-server-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-journal-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-ra-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-selector-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-server-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-service-extensions-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-activemq-artemis-tools-0:2.9.0-4.redhat_00010.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-apache-cxf-0:3.2.12-1.redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-apache-cxf-0:3.2.12-1.redhat_00001.1.el7eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-apache-cxf-rt-0:3.2.12-1.redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-apache-cxf-services-0:3.2.12-1.redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-apache-cxf-tools-0:3.2.12-1.redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el7eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-bouncycastle-mail-0:1.60.0-2.redhat_00002.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-bouncycastle-pkix-0:1.60.0-2.redhat_00002.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-bouncycastle-prov-0:1.60.0-2.redhat_00002.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el7eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 7 Server
  • +170 more not shown

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.

🔗 References (46)