Advisory Published

RHBA-2017:2548: Update to Red Hat JBoss Middleware images to fix log4j CVE-2017-5645

First published: Wed Aug 30 2017(Updated: )

Red Hat JBoss Middleware for OpenShift provides images for many of the Red Hat Middleware products, for use with OpenShift Container Platform, with on-premise or private cloud deployments.<br>This errata updates the following images by applying a fix for CVE-2017-5645 (<a href="https://access.redhat.com/security/cve/CVE-2017-5645):" target="_blank">https://access.redhat.com/security/cve/CVE-2017-5645):</a> Red Hat JBoss Enterprise Application Platform 6.4, Red Hat JBoss Enterprise Application Platform 7.0, Red Hat JBoss Web Server 3.0, Red Hat JBoss Web Server 3.1, Red Hat JBoss Data Grid 6.5, Red Hat JBoss BPM Suite 6.3 Process Server, Red Hat JBoss BPM Suite 6.4 Process Server, Red Hat JBoss BRMS 6.3 Decision Server, Red Hat JBoss BRMS 6.4 Decision Server, and Red Hat Single Sign-On 7.0.

Affected SoftwareAffected VersionHow to fix
Red Hat JBoss Enterprise Application Platform
Red Hat JBoss Web Server
Red Hat JBoss Data Grid
Red Hat JBoss BPM Suite
Red Hat JBoss Business Rules Management System
Red Hat Single Sign On

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of RHBA-2017:2548?

    The severity of RHBA-2017:2548 is categorized as moderate due to the vulnerabilities addressed.

  • How do I fix RHBA-2017:2548?

    To fix RHBA-2017:2548, update the affected Red Hat JBoss Middleware images to the latest version provided in the errata.

  • What vulnerability does RHBA-2017:2548 address?

    RHBA-2017:2548 addresses a fix for CVE-2017-5645 which impacts Red Hat JBoss Middleware components.

  • Which products are affected by RHBA-2017:2548?

    RHBA-2017:2548 affects multiple products including Red Hat JBoss Enterprise Application Platform and Red Hat Single Sign-On.

  • Is upgrading necessary for RHBA-2017:2548?

    Yes, upgrading is necessary to protect against vulnerabilities specified in RHBA-2017:2548.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203