RHSA-2018:2913: Moderate: Red Hat Decision Manager 7.1.0 bug fix and security update
Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.1.0 serves as an update to Red Hat Decision Manager 7.0.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): Resteasy: Yaml unmarshalling vulnerable to RCE (CVE-2016-9606) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Red Hat would like to thank Moritz Bechler (AgNO3 GmbH & Co. KG) for reporting CVE-2016-9606.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2913?
The severity of RHSA-2018:2913 is classified as moderate.
How do I fix RHSA-2018:2913?
To fix RHSA-2018:2913, upgrade to the latest version of Red Hat Decision Manager as provided in the security advisory.
What issues does RHSA-2018:2913 address?
RHSA-2018:2913 addresses potential vulnerabilities in Red Hat Decision Manager that could affect decision automation and business rules processing.
Is RHSA-2018:2913 applicable to all versions of Red Hat Decision Manager?
RHSA-2018:2913 applies to specific versions of Red Hat Decision Manager; consult the advisory for the precise affected versions.
What should I do if I cannot apply the fix for RHSA-2018:2913 immediately?
If you cannot apply the fix for RHSA-2018:2913 immediately, assess your risk and consider implementing compensating controls until the update can be applied.