RHSA-2023:2135HighCVSS 9.8

Red Hat Security Advisory: Red Hat Process Automation Manager 7.13.3 security update

Published
May 4, 2023
Last Modified
August 18, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2022-3782 — keycloak: path traversal via double URL encoding CVE-2022-4244 — codehaus-plexus: Directory Traversal CVE-2022-4245 — codehaus-plexus: XML External Entity (XXE) Injection CVE-2022-40149 — jettison: parser crash by stackoverflow CVE-2022-40150 — jettison: memory exhaustion via user-supplied XML or JSON data CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays CVE-2022-42889 — apache-commons-text: variable interpolation RCE CVE-2022-45693 — jettison: If the value in map is the map's self, the new new JSONObject(map) cause StackOverflowError which may lead to dos CVE-2022-46363 — CXF: directory listing / code exfiltration CVE-2022-46364 — CXF: SSRF Vulnerability CVE-2023-1108 — Undertow: Infinite loop in SslConduit during close

🎯 Affected products1

  • RHPAM 7.13.1 async

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: This flaw may be avoided by ensuring that any external inputs used with the Commons-Text lookup methods are sanitized properly. Untrusted input should always be thoroughly sanitized before using in any potentially risky situations.

🔗 References (9)