RHSA-2018:0466
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 2 security update
CVSS Metrics
- v3.0•HIGH•Score: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- redhat•mod_cluster
< 0:1.3.8-2.Final_redhat_2.1.ep7.el6 | < 0:1.3.8-2.Final_redhat_2.1.ep7.el7
- redhat•mod_cluster-tomcat7
< 0:1.3.8-2.Final_redhat_2.1.ep7.el6 | < 0:1.3.8-2.Final_redhat_2.1.ep7.el7
- redhat•mod_cluster-tomcat8
< 0:1.3.8-2.Final_redhat_2.1.ep7.el6 | < 0:1.3.8-2.Final_redhat_2.1.ep7.el7
- redhat•tomcat-native
< 0:1.2.8-11.redhat_11.ep7.el6 | < 0:1.2.8-11.redhat_11.ep7.el7
- redhat•tomcat-native-debuginfo
< 0:1.2.8-11.redhat_11.ep7.el6 | < 0:1.2.8-11.redhat_11.ep7.el7
- redhat•tomcat-vault
< 0:1.1.6-1.Final_redhat_1.1.ep7.el6 | < 0:1.1.6-1.Final_redhat_1.1.ep7.el7
- redhat•tomcat-vault-tomcat7
< 0:1.1.6-1.Final_redhat_1.1.ep7.el6 | < 0:1.1.6-1.Final_redhat_1.1.ep7.el7
- redhat•tomcat-vault-tomcat8
< 0:1.1.6-1.Final_redhat_1.1.ep7.el6 | < 0:1.1.6-1.Final_redhat_1.1.ep7.el7
- redhat•tomcat7
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-admin-webapps
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-docs-webapp
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-el-2.2-api
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-javadoc
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-jsp-2.2-api
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-jsvc
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-lib
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-log4j
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-selinux
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-servlet-3.0-api
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat7-webapps
< 0:7.0.70-25.ep7.el6 | < 0:7.0.70-25.ep7.el7
- redhat•tomcat8
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-admin-webapps
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-docs-webapp
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-el-2.2-api
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-javadoc
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-jsp-2.3-api
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-jsvc
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-lib
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-log4j
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-selinux
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-servlet-3.1-api
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
- redhat•tomcat8-webapps
< 0:8.0.36-29.ep7.el6 | < 0:8.0.36-29.ep7.el7
References (40)
- https://access.redhat.com/errata/RHSA-2018:0466
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/
- https://bugzilla.redhat.com/show_bug.cgi?id=1493220
- https://bugzilla.redhat.com/show_bug.cgi?id=1493222
- https://bugzilla.redhat.com/show_bug.cgi?id=1494283
- https://bugzilla.redhat.com/show_bug.cgi?id=1506523
- https://bugzilla.redhat.com/show_bug.cgi?id=1540824
- https://bugzilla.redhat.com/show_bug.cgi?id=1548282
- https://bugzilla.redhat.com/show_bug.cgi?id=1548289
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_0466.json
- https://access.redhat.com/security/cve/CVE-2017-12613
- https://www.cve.org/CVERecord?id=CVE-2017-12613
- https://nvd.nist.gov/vuln/detail/CVE-2017-12613
- http://www.apache.org/dist/apr/Announcement1.x.html
- https://access.redhat.com/security/cve/CVE-2017-12615
- https://www.cve.org/CVERecord?id=CVE-2017-12615
- https://nvd.nist.gov/vuln/detail/CVE-2017-12615
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.81
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://access.redhat.com/security/cve/CVE-2017-12616
- https://www.cve.org/CVERecord?id=CVE-2017-12616
- https://nvd.nist.gov/vuln/detail/CVE-2017-12616
- https://access.redhat.com/security/cve/CVE-2017-12617
- https://www.cve.org/CVERecord?id=CVE-2017-12617
- https://nvd.nist.gov/vuln/detail/CVE-2017-12617
- https://tomcat.apache.org/security-7.html
- https://tomcat.apache.org/security-8.html
- https://access.redhat.com/security/cve/CVE-2017-15698
- https://www.cve.org/CVERecord?id=CVE-2017-15698
- https://nvd.nist.gov/vuln/detail/CVE-2017-15698
- https://access.redhat.com/security/cve/CVE-2018-1304
- https://www.cve.org/CVERecord?id=CVE-2018-1304
- https://nvd.nist.gov/vuln/detail/CVE-2018-1304
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.85
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.50
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.28
- https://access.redhat.com/security/cve/CVE-2018-1305
- https://www.cve.org/CVERecord?id=CVE-2018-1305
- https://nvd.nist.gov/vuln/detail/CVE-2018-1305