RHBA-2017:2548: Update to Red Hat JBoss Middleware images to fix log4j CVE-2017-5645
Red Hat JBoss Middleware for OpenShift provides images for many of the Red Hat Middleware products, for use with OpenShift Container Platform, with on-premise or private cloud deployments.This errata updates the following images by applying a fix for CVE-2017-5645 (https://access.redhat.com/security/cve/CVE-2017-5645): Red Hat JBoss Enterprise Application Platform 6.4, Red Hat JBoss Enterprise Application Platform 7.0, Red Hat JBoss Web Server 3.0, Red Hat JBoss Web Server 3.1, Red Hat JBoss Data Grid 6.5, Red Hat JBoss BPM Suite 6.3 Process Server, Red Hat JBoss BPM Suite 6.4 Process Server, Red Hat JBoss BRMS 6.3 Decision Server, Red Hat JBoss BRMS 6.4 Decision Server, and Red Hat Single Sign-On 7.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHBA-2017:2548?
The severity of RHBA-2017:2548 is categorized as moderate due to the vulnerabilities addressed.
How do I fix RHBA-2017:2548?
To fix RHBA-2017:2548, update the affected Red Hat JBoss Middleware images to the latest version provided in the errata.
What vulnerability does RHBA-2017:2548 address?
RHBA-2017:2548 addresses a fix for CVE-2017-5645 which impacts Red Hat JBoss Middleware components.
Which products are affected by RHBA-2017:2548?
RHBA-2017:2548 affects multiple products including Red Hat JBoss Enterprise Application Platform and Red Hat Single Sign-On.
Is upgrading necessary for RHBA-2017:2548?
Yes, upgrading is necessary to protect against vulnerabilities specified in RHBA-2017:2548.