RHSA-2018:2840: Low: Red Hat JBoss Fuse/A-MQ 6.3 R9 security and bug fix update
Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform.This patch is an update to Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the References section below.Security fix(es): A-MQ Console: HTTPOnly and Secure attributes not set on cookies (CVE-2015-5183) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Red Hat would like to thank Naftali Rosenbaum (Comsec Consulting) for reporting CVE-2015-5183.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2840?
The severity of RHSA-2018:2840 is classified as low.
How do I fix RHSA-2018:2840?
To fix RHSA-2018:2840, you need to apply the latest patch for Red Hat JBoss Fuse 6.3.
What software is affected by RHSA-2018:2840?
RHSA-2018:2840 affects Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3.
What changes are included in the RHSA-2018:2840 patch?
The RHSA-2018:2840 patch includes various bug fixes documented in the accompanying patch notes.
Is RHSA-2018:2840 related to any security vulnerabilities?
RHSA-2018:2840 addresses vulnerabilities but is deemed to have a low severity level.