First published: Tue Nov 13 2018(Updated: )
Red Hat JBoss BRMS is a business rules management system for the<br>management, storage, creation, modification, and deployment of JBoss Rules.<br>This asynchronous patch is a security update for the RichFaces package in standalone versions of Red Hat JBoss BRMS 5.3.1.<br>Security Fix(es):<br><li> RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution (CVE-2018-14667)</li> See <a href="https://access.redhat.com/solutions/3660371" target="_blank">https://access.redhat.com/solutions/3660371</a> for specific information regarding this flaw.<br>For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Joao Filho Matos Figueiredo for reporting this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise BRMS Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2018:3581 is classified as a moderate severity security vulnerability.
To fix RHSA-2018:3581, you need to apply the latest security updates for the RichFaces package in Red Hat JBoss BRMS 5.3.1.
RHSA-2018:3581 affects standalone versions of Red Hat JBoss BRMS 5.3.1.
Yes, it's necessary to update for RHSA-2018:3581 to mitigate security risks associated with the vulnerability.
RHSA-2018:3581 impacts the RichFaces package within Red Hat JBoss BRMS.