RHSA-2020:2506HighCVSS 7.0
Red Hat Security Advisory: Red Hat JBoss Web Server 5.3.1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-9484 — tomcat: deserialization flaw in session persistence storage leading to RCE
🎯 Affected products47
- Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el6jws.src as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el7jws.src as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-0:9.0.30-4.redhat_5.1.el8jws.src as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-admin-webapps-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-admin-webapps-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-admin-webapps-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-docs-webapp-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-docs-webapp-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-docs-webapp-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-el-3.0-api-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-el-3.0-api-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-el-3.0-api-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-javadoc-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-javadoc-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-jsp-2.3-api-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-jsp-2.3-api-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-jsp-2.3-api-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-lib-0:9.0.30-4.redhat_5.1.el6jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-lib-0:9.0.30-4.redhat_5.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 7 Server
- jws5-tomcat-lib-0:9.0.30-4.redhat_5.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.3 for RHEL 8
- jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws.i686 as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws.src as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws.x86_64 as a component of Red Hat JBoss Web Server 5.3 for RHEL 6 Server
- +17 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.