RHSA-2020:5344HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3.4 security update

Published
December 3, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-25638 — hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used CVE-2020-25644 — wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)

🎯 Affected products1

  • Red Hat JBoss Enterprise Application Platform 7

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Workaround: Set hibernate.use_sql_comments to false, which is the default value, or use named parameters instead of literals. Please refer to details in https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#configurations-logging and https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#sql-query-parameters. Workaround: There is currently no known mitigation for this issue. Workaround: There is currently no known mitigation for this flaw.

🔗 References (20)