First published: Thu Mar 22 2018(Updated: )
Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.<br>This release of Red Hat JBoss BRMS 6.4.9 serves as a replacement for Red Hat JBoss BRMS 6.4.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) (CVE-2017-15095)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Liao Xinxi (NSFOCUS) for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise BRMS Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:0576 is classified as important.
To fix RHSA-2018:0576, update your Red Hat JBoss BRMS to version 6.4.9.
RHSA-2018:0576 affects Red Hat JBoss BRMS 6.4.8 and earlier versions.
RHSA-2018:0576 addresses various bug fixes and enhancements in JBoss BRMS.
No specific workaround is mentioned for RHSA-2018:0576; applying the update is recommended.