RHSA-2020:2062HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2 security update

Published
May 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2018-14371 — mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter CVE-2019-10174 — infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods

🎯 Affected products1

  • Red Hat JBoss EAP 7.2

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. You must restart the JBoss server process for the update to take effect. The References section of this erratum contains a download link (you must log in to download the update). Workaround: There is no currently known mitigation for this flaw. Workaround: There is no known mitigation for this issue.

🔗 References (8)