First published: Mon Feb 18 2019(Updated: )
Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.<br>This release of Red Hat JBoss Enterprise Application Platform 7.1.6 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.5, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> wildfly-core: Cross-site scripting (XSS) in JBoss Management Console (CVE-2018-10934)</li> <li> undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer (CVE-2018-14642)</li> <li> dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents (CVE-2018-1000632)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-activemq-artemis | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-apache-cxf | <3.1.16-2.redhat_2.1.ep7.el6 | 3.1.16-2.redhat_2.1.ep7.el6 |
redhat/eap7-dom4j | <2.1.1-1.redhat_00001.1.ep7.el6 | 2.1.1-1.redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jackson-databind | <2.8.11.3-1.redhat_00001.1.ep7.el6 | 2.8.11.3-1.redhat_00001.1.ep7.el6 |
redhat/eap7-jandex | <2.0.5-1.Final_redhat_1.1.ep7.el6 | 2.0.5-1.Final_redhat_1.1.ep7.el6 |
redhat/eap7-jberet | <1.2.7-1.Final_redhat_00001.1.ep7.el6 | 1.2.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-ejb-client | <4.0.12-1.Final_redhat_00001.1.ep7.el6 | 4.0.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-logmanager | <2.0.11-1.Final_redhat_00001.1.ep7.el6 | 2.0.11-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-modules | <1.6.7-1.Final_redhat_00001.1.ep7.el6 | 1.6.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-security-negotiation | <3.0.5-1.Final_redhat_00001.1.ep7.el6 | 3.0.5-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jbossws-common | <3.1.7-1.Final_redhat_00001.1.ep7.el6 | 3.1.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-picketlink-bindings | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-federation | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-undertow | <1.4.18-10.SP11_redhat_00001.1.ep7.el6 | 1.4.18-10.SP11_redhat_00001.1.ep7.el6 |
redhat/eap7-undertow-jastow | <2.0.7-1.Final_redhat_00001.1.ep7.el6 | 2.0.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly | <7.1.6-4.GA_redhat_00002.1.ep7.el6 | 7.1.6-4.GA_redhat_00002.1.ep7.el6 |
redhat/eap7-wildfly-common | <1.2.1-1.Final_redhat_00001.1.ep7.el6 | 1.2.1-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-elytron | <1.1.12-1.Final_redhat_00001.1.ep7.el6 | 1.1.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-elytron-tool | <1.0.9-1.Final_redhat_00001.1.ep7.el6 | 1.0.9-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-javadocs | <7.1.6-2.GA_redhat_00002.1.ep7.el6 | 7.1.6-2.GA_redhat_00002.1.ep7.el6 |
redhat/eap7-wildfly-web-console-eap | <2.9.19-1.Final_redhat_00001.1.ep7.el6 | 2.9.19-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-cli | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-commons | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-core-client | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-dto | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-hornetq-protocol | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-hqclient-protocol | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-jdbc-store | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-jms-client | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-jms-server | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-journal | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-native | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-ra | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-selector | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-server | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-activemq-artemis-service-extensions | <1.5.5.015-1.redhat_00001.1.ep7.el6 | 1.5.5.015-1.redhat_00001.1.ep7.el6 |
redhat/eap7-apache-cxf | <3.1.16-2.redhat_2.1.ep7.el6 | 3.1.16-2.redhat_2.1.ep7.el6 |
redhat/eap7-apache-cxf-rt | <3.1.16-2.redhat_2.1.ep7.el6 | 3.1.16-2.redhat_2.1.ep7.el6 |
redhat/eap7-apache-cxf-services | <3.1.16-2.redhat_2.1.ep7.el6 | 3.1.16-2.redhat_2.1.ep7.el6 |
redhat/eap7-apache-cxf-tools | <3.1.16-2.redhat_2.1.ep7.el6 | 3.1.16-2.redhat_2.1.ep7.el6 |
redhat/eap7-dom4j | <2.1.1-1.redhat_00001.1.ep7.el6 | 2.1.1-1.redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate-core | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate-entitymanager | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate-envers | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate-infinispan | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-hibernate-java8 | <5.1.17-1.Final_redhat_00001.1.ep7.el6 | 5.1.17-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-common-api | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-common-impl | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-common-spi | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-core-api | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-core-impl | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-deployers-common | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-jdbc | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-ironjacamar-validator | <1.4.12-1.Final_redhat_00001.1.ep7.el6 | 1.4.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jackson-databind | <2.8.11.3-1.redhat_00001.1.ep7.el6 | 2.8.11.3-1.redhat_00001.1.ep7.el6 |
redhat/eap7-jandex | <2.0.5-1.Final_redhat_1.1.ep7.el6 | 2.0.5-1.Final_redhat_1.1.ep7.el6 |
redhat/eap7-jberet | <1.2.7-1.Final_redhat_00001.1.ep7.el6 | 1.2.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jberet-core | <1.2.7-1.Final_redhat_00001.1.ep7.el6 | 1.2.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-ejb-client | <4.0.12-1.Final_redhat_00001.1.ep7.el6 | 4.0.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-logmanager | <2.0.11-1.Final_redhat_00001.1.ep7.el6 | 2.0.11-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-modules | <1.6.7-1.Final_redhat_00001.1.ep7.el6 | 1.6.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jboss-security-negotiation | <3.0.5-1.Final_redhat_00001.1.ep7.el6 | 3.0.5-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-jbossws-common | <3.1.7-1.Final_redhat_00001.1.ep7.el6 | 3.1.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-compensations | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-jbosstxbridge | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-jbossxts | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-jts-idlj | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-jts-integration | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-restat-api | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-restat-bridge | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-restat-integration | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-restat-util | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-narayana-txframework | <5.5.34-1.Final_redhat_00001.1.ep7.el6 | 5.5.34-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-picketlink-api | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-bindings | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-common | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-config | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-federation | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-idm-api | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-idm-impl | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-idm-simple-schema | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-impl | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-picketlink-wildfly8 | <2.5.5-15.SP12_redhat_3.1.ep7.el6 | 2.5.5-15.SP12_redhat_3.1.ep7.el6 |
redhat/eap7-undertow | <1.4.18-10.SP11_redhat_00001.1.ep7.el6 | 1.4.18-10.SP11_redhat_00001.1.ep7.el6 |
redhat/eap7-undertow-jastow | <2.0.7-1.Final_redhat_00001.1.ep7.el6 | 2.0.7-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly | <7.1.6-4.GA_redhat_00002.1.ep7.el6 | 7.1.6-4.GA_redhat_00002.1.ep7.el6 |
redhat/eap7-wildfly-common | <1.2.1-1.Final_redhat_00001.1.ep7.el6 | 1.2.1-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-elytron | <1.1.12-1.Final_redhat_00001.1.ep7.el6 | 1.1.12-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-elytron-tool | <1.0.9-1.Final_redhat_00001.1.ep7.el6 | 1.0.9-1.Final_redhat_00001.1.ep7.el6 |
redhat/eap7-wildfly-javadocs | <7.1.6-2.GA_redhat_00002.1.ep7.el6 | 7.1.6-2.GA_redhat_00002.1.ep7.el6 |
redhat/eap7-wildfly-modules | <7.1.6-4.GA_redhat_00002.1.ep7.el6 | 7.1.6-4.GA_redhat_00002.1.ep7.el6 |
redhat/eap7-wildfly-web-console-eap | <2.9.19-1.Final_redhat_00001.1.ep7.el6 | 2.9.19-1.Final_redhat_00001.1.ep7.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.