Lucene search

K
redhatRedHatRHSA-2018:3529
HistoryNov 08, 2018 - 3:29 p.m.

(RHSA-2018:3529) Moderate: Red Hat JBoss Enterprise Application Platform 7.1.5 on RHEL 6 security update

2018-11-0815:29:11
access.redhat.com
568

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.5%

Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.

This release of Red Hat JBoss Enterprise Application Platform 7.1.5 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.4, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • wildfly-iiop-openjdk: iiop does not honour strict transport confidentiality (CVE-2018-14627)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHat6noarcheap7-jboss-server-migration-eap7.0-to-eap7.1< 1.0.7-1.Final_redhat_00001.1.ep7.el6eap7-jboss-server-migration-eap7.0-to-eap7.1-1.0.7-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-undertow-server< 1.0.2-1.Final_redhat_00001.1.ep7.el6eap7-undertow-server-1.0.2-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-wildfly-javadocs< 7.1.5-2.GA_redhat_00002.1.ep7.el6eap7-wildfly-javadocs-7.1.5-2.GA_redhat_00002.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-ironjacamar-common-api< 1.4.11-1.Final_redhat_00001.1.ep7.el6eap7-ironjacamar-common-api-1.4.11-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-undertow< 1.4.18-8.SP9_redhat_00001.1.ep7.el6eap7-undertow-1.4.18-8.SP9_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-jboss-marshalling-river< 2.0.6-1.Final_redhat_00001.1.ep7.el6eap7-jboss-marshalling-river-2.0.6-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-hibernate< 5.1.16-1.Final_redhat_00001.1.ep7.el6eap7-hibernate-5.1.16-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-wildfly-modules< 7.1.5-4.GA_redhat_00002.1.ep7.el6eap7-wildfly-modules-7.1.5-4.GA_redhat_00002.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-hibernate-entitymanager< 5.1.16-1.Final_redhat_00001.1.ep7.el6eap7-hibernate-entitymanager-5.1.16-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
RedHat6noarcheap7-jboss-server-migration-wildfly10.1< 1.0.7-1.Final_redhat_00001.1.ep7.el6eap7-jboss-server-migration-wildfly10.1-1.0.7-1.Final_redhat_00001.1.ep7.el6.noarch.rpm
Rows per page:
1-10 of 861

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.5%