First published: Tue Dec 11 2018(Updated: )
Red Hat Fuse provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat A-MQ is a standards compliant messaging system that is tailored for use in mission critical applications.<br>This patch is an update to Red Hat Fuse 6.3 and Red Hat A-MQ 6.3. It includes bug fixes, which are documented in the patch notes accompanying the package on the download page. See the download link given in the references section below.<br>Security fix(es):<br><li> hibernate-validator: Privilege escalation when running under the security manager (CVE-2017-7536)</li> <li> jolokia-core: jolokia: Cross site scripting in the HTTP servlet (CVE-2018-1000129)</li> <li> cxf-core: apache-cxf: TLS hostname verification does not work correctly with com.sun.net.ssl.* (CVE-2018-8039)</li> CVE-2017-7536 issue was discovered by Gunnar Morling (Red Hat).<br>For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Fuse | ||
Red Hat AMQ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:3817 is classified as important.
To fix RHSA-2018:3817, you should apply the available updates for Red Hat Fuse and Red Hat A-MQ.
The affected products for RHSA-2018:3817 include Red Hat JBoss Fuse and Red Hat A-MQ.
RHSA-2018:3817 was released in December 2018.
RHSA-2018:3817 addresses various security vulnerabilities within Red Hat Fuse and Red Hat A-MQ.