RHSA-2020:2511HighCVSS 8.1

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.1 Security update

Published
June 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2018-14371 — mojarra: Path traversal in ResourceManager.java:getLocalePrefix() via the loc parameter CVE-2019-0205 — thrift: Endless loop when feed with specific input data CVE-2019-0210 — thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol CVE-2019-10172 — jackson-mapper-asl: XML external entity similar to CVE-2016-3720 CVE-2019-12423 — cxf: OpenId Connect token service does not properly validate the clientId CVE-2019-14887 — wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use CVE-2019-17573 — cxf: reflected XSS in the services listing page CVE-2020-1695 — resteasy: Improper validation of response header in MediaTypeHeaderDelegate.java class CVE-2020-1719 — Wildfly: EJBContext principal is not popped back after invoking another EJB using a different Security Domain CVE-2020-1729 — SmallRye: SecuritySupport class is incorrectly public and contains a static method to access the current threads context class loader CVE-2020-1745 — undertow: AJP File Read/Inclusion Vulnerability CVE-2020-1757 — undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass CVE-2020-6950 — Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 CVE-2020-7226 — cryptacular: excessive memory allocation during a decode operation CVE-2020-8840 — jackson-databind: Lacks certain xbean-reflect/JNDI blocking CVE-2020-9546 — jackson-databind: Serialization gadgets in shaded-hikari-config CVE-2020-9547 — jackson-databind: Serialization gadgets in ibatis-sqlmap CVE-2020-9548 — jackson-databind: Serialization gadgets in anteros-core CVE-2020-10688 — RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack CVE-2020-10705 — undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header CVE-2020-10719 — undertow: invalid HTTP request with large chunk size

🎯 Affected products200

  • Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-cli-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-commons-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-core-client-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-dto-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-hornetq-protocol-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-hqclient-protocol-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-jdbc-store-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-jms-client-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-jms-server-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-journal-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-ra-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-selector-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-server-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-service-extensions-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-activemq-artemis-tools-0:2.9.0-4.redhat_00010.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-apache-cxf-0:3.3.5-1.redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-apache-cxf-0:3.3.5-1.redhat_00001.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-apache-cxf-rt-0:3.3.5-1.redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-apache-cxf-services-0:3.3.5-1.redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-apache-cxf-tools-0:3.3.5-1.redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-bouncycastle-0:1.60.0-2.redhat_00002.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-bouncycastle-mail-0:1.60.0-2.redhat_00002.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-bouncycastle-pkix-0:1.60.0-2.redhat_00002.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-bouncycastle-prov-0:1.60.0-2.redhat_00002.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-codehaus-jackson-0:1.9.13-10.redhat_00007.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • +170 more not shown

✅ Remediation

Before applying this update, ensure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: There is no currently known mitigation for this flaw. Workaround: Avoid using an OpenSSL security provider and instead use the default configuration or regular JSSE provider with 'TLS'. Workaround: Mitigate this flaw by disabling the service listing altogether; via setting the "hide-service-list-page" servlet parameter to "true". Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 Workaround: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via setting "alwaysUseFullPath". Workaround: There is currently no known mitigation for this security flaw.

🔗 References (77)