RHSA-2020:2783HighCVSS 7.6

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.23 security update

Published
July 1, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2019-14885 — EAP: Vault system property security attribute value is revealed on CLI 'reload' command CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 6.4

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). You must restart the JBoss server process for the update to take effect. Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251

🔗 References (13)