Lucene search

K
redhatRedHatRHSA-2020:3587
HistorySep 01, 2020 - 2:37 p.m.

(RHSA-2020:3587) Important: Red Hat JBoss Fuse/A-MQ 6.3 R17 security and bug fix update

2020-09-0114:37:01
access.redhat.com
51

0.033 Low

EPSS

Percentile

91.3%

Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.

This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.

Security fix(es):

  • commons-beanutils: apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)

  • Camel: server-side template injection and arbitrary file disclosure on templating components (CVE-2020-11994)

  • hawtio: server side request forgery via initial /proxy/ substring of a URI (CVE-2019-9827)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.