RHSA-2020:2487HighCVSS 7.0
Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 9 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-9484 — tomcat: deserialization flaw in session persistence storage leading to RCE
🎯 Affected products1
- Red Hat JBoss Web Server 3.1
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2020:2487
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=3.1
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1838332
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_2487.json