RHSA-2020:2060HighCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.8 on RHEL 8 security update

Published
May 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1732 — Soteria: security identity corruption across concurrent threads CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size

🎯 Affected products200

  • Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-cli-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-commons-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-core-client-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-dto-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-hornetq-protocol-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-hqclient-protocol-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jdbc-store-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jms-client-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-jms-server-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-journal-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-ra-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-selector-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-server-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-service-extensions-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-activemq-artemis-tools-0:2.9.0-4.redhat_00010.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-apache-cxf-0:3.2.12-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-apache-cxf-0:3.2.12-1.redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-apache-cxf-rt-0:3.2.12-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-apache-cxf-services-0:3.2.12-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-apache-cxf-tools-0:3.2.12-1.redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-bouncycastle-mail-0:1.60.0-2.redhat_00002.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-bouncycastle-pkix-0:1.60.0-2.redhat_00002.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-bouncycastle-prov-0:1.60.0-2.redhat_00002.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el8eap.src as a component of Red Hat JBoss EAP 7.2 for RHEL 8
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.

🔗 References (46)