RHSA-2018:3519: Critical: Red Hat JBoss SOA Platform security update
Red Hat JBoss SOA Platform is the next-generation ESB and business process<br>automation infrastructure. Red Hat JBoss SOA Platform allows IT to leverage<br>existing (MoM and EAI), modern (SOA and BPM-Rules), and future (EDA and<br>CEP) integration methodologies to dramatically improve business process<br>execution speed and quality.<br>This asynchronous patch is a security update for the RichFaces package in Red Hat JBoss SOA Platform 5.3.1.<br>Security Fix(es):<br><li> RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution (CVE-2018-14667)</li> See <a href="https://access.redhat.com/solutions/3660371" target="blank">https://access.redhat.com/solutions/3660371</a> for specific information regarding this flaw.<br>For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Joao Filho Matos Figueiredo for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:3519?
The severity of RHSA-2018:3519 is rated as moderate.
What are the affected versions of Red Hat JBoss SOA Platform in RHSA-2018:3519?
RHSA-2018:3519 affects various versions of Red Hat JBoss SOA Platform without specifying individual version numbers.
How do I fix RHSA-2018:3519?
To fix RHSA-2018:3519, you should apply the recommended updates provided by Red Hat.
What is the nature of the vulnerability in RHSA-2018:3519?
RHSA-2018:3519 addresses a security vulnerability that could potentially allow unauthorized access.
Is there a workaround for RHSA-2018:3519?
There are no specific workarounds recommended for RHSA-2018:3519 aside from applying the security updates.