Lucene search

K
redhatRedHatRHSA-2020:5174
HistoryNov 23, 2020 - 1:23 p.m.

(RHSA-2020:5174) Important: Red Hat JBoss Enterprise Application Platform 7.3.3 security update

2020-11-2313:23:34
access.redhat.com
47

0.004 Low

EPSS

Percentile

72.1%

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java
applications based on the WildFly application runtime.

This asynchronous patch is a security update for Red Hat JBoss Enterprise
Application Platform 7.3.

Security Fix(es):

  • hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments
    and JPQL String literals are used (CVE-2020-25638)

For more details about the security issue(s), including the impact, a CVSS score,
acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.