RHSA-2022:7273MediumCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.0 release and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-22696 — cxf: OAuth 2 authorization service vulnerable to DDos attacks CVE-2021-30468 — CXF: Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter CVE-2021-43980 — Tomcat: Information disclosure CVE-2022-23181 — tomcat: local privilege escalation vulnerability
🎯 Affected products1
- JWS 5.7.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2022:7273
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1946341
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973392
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047417
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7273.json