Lucene search

K
redhatRedHatRHSA-2018:2425
HistoryAug 15, 2018 - 11:19 a.m.

(RHSA-2018:2425) Important: Red Hat JBoss Enterprise Application Platform 7.1 security update

2018-08-1511:19:19
access.redhat.com
21

0.013 Low

EPSS

Percentile

85.7%

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on Wildfly.

This release of Red Hat JBoss Enterprise Application Platform 7.1.4 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.3, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service (CVE-2018-10237)

  • bouncycastle: flaw in the low-level interface to RSA key pair generator (CVE-2018-1000180)

  • cxf: Improper size validation in message attachment header for JAX-WS and JAX-RS services (CVE-2017-12624)

  • wildfly: wildfly-core: Path traversal can allow the extraction of .war archives to write arbitrary files (CVE-2018-10862)

  • cxf-core: apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* (CVE-2018-8039)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.