RHSA-2017:0245
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform security update
CVSS Metrics
- v3.0•HIGH•Score: 7CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•apache-cxf
< 0:2.7.18-5.SP4_redhat_1.1.ep6.el7
- redhat•hornetq
< 0:2.3.25-18.SP16_redhat_1.1.ep6.el7
- redhat•infinispan
< 0:5.2.20-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-jdbc
< 0:5.2.20-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-remote
< 0:5.2.20-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-client-hotrod
< 0:5.2.20-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-core
< 0:5.2.20-1.Final_redhat_1.1.ep6.el7
- redhat•jboss-as-appclient
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-cli
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-client-all
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-clustering
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-cmp
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-configadmin
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-connector
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-console
< 0:2.5.15-1.Final_redhat_1.1.ep6.el7
- redhat•jboss-as-controller
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-controller-client
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-core-security
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-deployment-repository
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-deployment-scanner
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-domain-http
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-domain-management
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ee
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ee-deployment
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ejb3
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-embedded
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-host-controller
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jacorb
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jaxr
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jaxrs
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jdr
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jmx
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jpa
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jsf
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jsr77
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-logging
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-mail
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-management-client-content
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-messaging
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-modcluster
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-naming
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-network
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-osgi
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-osgi-configadmin
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-osgi-service
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-picketlink
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-platform-mbean
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-pojo
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-process-controller
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-protocol
< 0:7.5.13-2.Final_redhat_2.1.ep6.el7
Showing first 50 affected entries in server-rendered view.
References (28)
- https://access.redhat.com/errata/RHSA-2017:0245
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Application_Platform/
- https://bugzilla.redhat.com/show_bug.cgi?id=1380852
- https://bugzilla.redhat.com/show_bug.cgi?id=1388240
- https://bugzilla.redhat.com/show_bug.cgi?id=1397484
- https://bugzilla.redhat.com/show_bug.cgi?id=1400344
- https://bugzilla.redhat.com/show_bug.cgi?id=1401972
- https://bugzilla.redhat.com/show_bug.cgi?id=1403852
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_0245.json
- https://access.redhat.com/security/cve/CVE-2016-6816
- https://www.cve.org/CVERecord?id=CVE-2016-6816
- https://nvd.nist.gov/vuln/detail/CVE-2016-6816
- https://access.redhat.com/articles/2991951
- https://access.redhat.com/solutions/2891171
- https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.48
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.73
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.39
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.8
- https://access.redhat.com/security/cve/CVE-2016-7061
- https://www.cve.org/CVERecord?id=CVE-2016-7061
- https://nvd.nist.gov/vuln/detail/CVE-2016-7061
- https://access.redhat.com/security/cve/CVE-2016-8627
- https://www.cve.org/CVERecord?id=CVE-2016-8627
- https://nvd.nist.gov/vuln/detail/CVE-2016-8627
- https://access.redhat.com/security/cve/CVE-2016-8656
- https://www.cve.org/CVERecord?id=CVE-2016-8656
- https://nvd.nist.gov/vuln/detail/CVE-2016-8656