RHSA-2020:3141HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3 security update

Published
July 23, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-10740 — wildfly: unsafe deserialization in Wildfly Enterprise Java Beans CVE-2020-14297 — wildfly: Some EJB transaction objects may get accumulated causing Denial of Service CVE-2020-14307 — wildfly: EJB SessionOpenInvocations may not be removed properly after a response is received causing Denial of Service

🎯 Affected products44

  • Red Hat JBoss EAP 7.3 for BaseOS-8
  • Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el7eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-jboss-ejb-client-0:4.0.33-2.SP1_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el7eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el8.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-0:7.3.1-7.GA_redhat_00004.1.el8.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.el6eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.el7eap.src as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.el8eap.src as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-http-client-common-0:1.0.21-1.Final_redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-http-client-common-0:1.0.21-1.Final_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-http-client-common-0:1.0.21-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-http-ejb-client-0:1.0.21-1.Final_redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-http-ejb-client-0:1.0.21-1.Final_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-http-ejb-client-0:1.0.21-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-http-naming-client-0:1.0.21-1.Final_redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-http-naming-client-0:1.0.21-1.Final_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-http-naming-client-0:1.0.21-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • eap7-wildfly-http-transaction-client-0:1.0.21-1.Final_redhat_00001.1.el6eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 6 Server
  • eap7-wildfly-http-transaction-client-0:1.0.21-1.Final_redhat_00001.1.el7eap.noarch as a component of Red Hat JBoss EAP 7.3 for RHEL 7 Server
  • eap7-wildfly-http-transaction-client-0:1.0.21-1.Final_redhat_00001.1.el8eap.noarch as a component of Red Hat JBoss EAP 7.3 for BaseOS-8
  • +14 more not shown

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. You must restart the JBoss server process for the update to take effect. For details about how to apply this update, see: https://access.redhat.com/articles/11258 Workaround: There is currently no known mitigation for this issue.

🔗 References (8)