RHSA-2020:4247MediumCVSS 5.9

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.3 security update

Published
October 13, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2020-1954 — cxf: JMX integration is vulnerable to a MITM attack CVE-2020-14299 — picketbox: JBoss EAP reload to admin-only mode allows authentication bypass CVE-2020-14338 — wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl CVE-2020-14340 — xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS

🎯 Affected products1

  • EAP 7.3.3

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect.

🔗 References (42)