RHSA-2021:3516HighCVSS 7.5

Red Hat Security Advisory: EAP XP 2 security update to CVE fixes in the EAP 7.3.x base

Published
September 13, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2021-3597 — undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS CVE-2021-3644 — wildfly-core: Invalid Sensitivity Classification of Vault Expression CVE-2021-3690 — undertow: buffer leak on incoming websocket PONG message may lead to DoS CVE-2021-28170 — jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate CVE-2021-29425 — apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6

🎯 Affected products1

  • Red Hat EAP-XP 2.0.0 via EAP 7.3.x base

✅ Remediation

This advisory is informational only. There are no code changes associated with it. No action is required.

🔗 References (10)