Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.0 security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2021-2471 — mysql-connector-java: unauthorized access to critical CVE-2021-3642 — wildfly-elytron: possible timing attack in ScramServer CVE-2021-3644 — wildfly-core: Invalid Sensitivity Classification of Vault Expression CVE-2021-3717 — wildfly: incorrect JBOSS_LOCAL_USER challenge location may lead to giving access to all the local users CVE-2021-22569 — protobuf-java: potential DoS in the parsing procedure for binary data CVE-2021-36373 — ant: excessive memory allocation when reading a specially crafted TAR archive CVE-2021-37136 — netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data CVE-2021-37137 — netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way CVE-2021-37714 — jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck CVE-2021-43797 — netty: control chars in header names may lead to HTTP request smuggling CVE-2022-22950 — spring-expression: Denial of service via specially crafted SpEL expression CVE-2022-25647 — com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
🎯 Affected products1
- RHPAM 7.13.0 async
✅ Remediation
For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process. The References section of this erratum contains a download link (you must log in to download the update).
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2022:5903
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1976052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981407
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1982336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004135
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2020583
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2080850
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5903.json