First published: Thu Jul 18 2019(Updated: )
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes <a href="https://access.redhat.com/security/cve/CVE-2017-17485">CVE-2017-17485</a>, <a href="https://access.redhat.com/security/cve/CVE-2017-7525">CVE-2017-7525</a>, <a href="https://access.redhat.com/security/cve/CVE-2017-15095">CVE-2017-15095</a>, <a href="https://access.redhat.com/security/cve/CVE-2018-5968">CVE-2018-5968</a>, <a href="https://access.redhat.com/security/cve/CVE-2018-7489">CVE-2018-7489</a>, <a href="https://access.redhat.com/security/cve/CVE-2018-1000873">CVE-2018-1000873</a>, <a href="https://access.redhat.com/security/cve/CVE-2019-12086">CVE-2019-12086</a> reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-codehaus-jackson | <0:1.9.13-9.redhat_00006.1.el6ea | 0:1.9.13-9.redhat_00006.1.el6ea |
redhat/eap7-codehaus-jackson | <0:1.9.13-9.redhat_00006.1.el7ea | 0:1.9.13-9.redhat_00006.1.el7ea |
redhat/eap7-codehaus-jackson | <0:1.9.13-9.redhat_00006.1.el8ea | 0:1.9.13-9.redhat_00006.1.el8ea |
Redhat Jboss Enterprise Application Platform | =7.2.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
IBM Disconnected Log Collector | <=v1.0 - v1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-10202 is a deserialization vulnerability in Red Hat JBoss Enterprise Application Platform (EAP) that allows remote attackers to execute arbitrary code.
The severity of CVE-2019-10202 is high with a CVSS score of 8.1.
The affected software is Red Hat JBoss Enterprise Application Platform (EAP) version 7 with Codehaus 1.9.x implementation.
To fix CVE-2019-10202, update the affected software to version 1.9.13-9.redhat_00006.1.el6ea for el6, version 1.9.13-9.redhat_00006.1.el7ea for el7, or version 1.9.13-9.redhat_00006.1.el8ea for el8.
Yes, you can find more information about CVE-2019-10202 at the following references: 1. [CVE-2017-17485](https://access.redhat.com/security/cve/CVE-2017-17485) 2. [CVE-2017-7525](https://access.redhat.com/security/cve/CVE-2017-7525) 3. [CVE-2017-15095](https://access.redhat.com/security/cve/CVE-2017-15095)