First published: Wed Aug 15 2018(Updated: )
Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.<br>This release of Red Hat JBoss BRMS 6.4.11 serves as a replacement for Red Hat JBoss BRMS 6.4.10, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Chris McCown for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise BRMS Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:2420 is classified as Important.
To fix RHSA-2018:2420, you need to update to Red Hat JBoss BRMS 6.4.11 or later.
RHSA-2018:2420 affects Red Hat JBoss BRMS 6.4.10 and earlier versions.
There is no official workaround for RHSA-2018:2420; upgrading to the fixed version is recommended.
RHSA-2018:2420 addresses bug fixes and enhancements for Red Hat JBoss BRMS.