RHSA-2017:2636
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.17 update on RHEL 7
CVSS Metrics
- v3.0•HIGH•Score: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•apache-cxf
< 0:2.7.18-7.SP6_redhat_1.1.ep6.el7
- redhat•codehaus-jackson
< 0:1.9.9-11.redhat_5.1.ep6.el7
- redhat•codehaus-jackson-core-asl
< 0:1.9.9-11.redhat_5.1.ep6.el7
- redhat•codehaus-jackson-jaxrs
< 0:1.9.9-11.redhat_5.1.ep6.el7
- redhat•codehaus-jackson-mapper-asl
< 0:1.9.9-11.redhat_5.1.ep6.el7
- redhat•codehaus-jackson-xc
< 0:1.9.9-11.redhat_5.1.ep6.el7
- redhat•hibernate4-core-eap6
< 0:4.2.27-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-eap6
< 0:4.2.27-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-entitymanager-eap6
< 0:4.2.27-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-envers-eap6
< 0:4.2.27-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-infinispan-eap6
< 0:4.2.27-1.Final_redhat_1.1.ep6.el7
- redhat•hornetq
< 0:2.3.25-22.SP20_redhat_1.1.ep6.el7
- redhat•infinispan
< 0:5.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-jdbc
< 0:5.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-remote
< 0:5.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-client-hotrod
< 0:5.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-core
< 0:5.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•jboss-as-appclient
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-cli
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-client-all
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-clustering
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-cmp
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-configadmin
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-connector
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-controller
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-controller-client
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-core-security
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-deployment-repository
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-deployment-scanner
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-domain-http
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-domain-management
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-ee
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-ee-deployment
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-ejb3
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-embedded
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-host-controller
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jacorb
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jaxr
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jaxrs
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jdr
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jmx
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jpa
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jsf
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-jsr77
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-logging
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-mail
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-management-client-content
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-messaging
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-modcluster
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
- redhat•jboss-as-naming
< 0:7.5.17-2.Final_redhat_4.1.ep6.el7
Showing first 50 affected entries in server-rendered view.
References (19)
- https://access.redhat.com/errata/RHSA-2017:2636
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform?version=6.4/
- https://bugzilla.redhat.com/show_bug.cgi?id=1443635
- https://bugzilla.redhat.com/show_bug.cgi?id=1459158
- https://bugzilla.redhat.com/show_bug.cgi?id=1462702
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_2636.json
- https://access.redhat.com/security/cve/CVE-2017-5645
- https://www.cve.org/CVERecord?id=CVE-2017-5645
- https://nvd.nist.gov/vuln/detail/CVE-2017-5645
- https://access.redhat.com/security/cve/CVE-2017-5664
- https://www.cve.org/CVERecord?id=CVE-2017-5664
- https://nvd.nist.gov/vuln/detail/CVE-2017-5664
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.78
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.44
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.15
- https://access.redhat.com/security/cve/CVE-2017-7525
- https://www.cve.org/CVERecord?id=CVE-2017-7525
- https://nvd.nist.gov/vuln/detail/CVE-2017-7525