Lucene search

K
redhatRedHatRHSA-2019:0362
HistoryFeb 18, 2019 - 3:33 p.m.

(RHSA-2019:0362) Moderate: Red Hat JBoss Enterprise Application Platform 7.1.6 security update

2019-02-1815:33:24
access.redhat.com
73

0.003 Low

EPSS

Percentile

71.0%

Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.

This release of Red Hat JBoss Enterprise Application Platform 7.1.6 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.5, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • wildfly-core: Cross-site scripting (XSS) in JBoss Management Console (CVE-2018-10934)

  • undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer (CVE-2018-14642)

  • dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents (CVE-2018-1000632)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.