First published: Mon Jun 10 2019(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on JBoss Application Server 7. <br>This release of Red Hat JBoss Enterprise Application Platform 7.2.2 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.2.1, and includes bug fixes and enhancements. Refer to the Red Hat JBoss Enterprise Application Platform 7.2.2 Release Notes for information on the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> picketlink: reflected XSS in SAMLRequest via RelayState parameter (CVE-2019-3872)</li> <li> picketlink: URL injection via xinclude parameter (CVE-2019-3873)</li> <li> undertow: leak credentials to log files UndertowLogger.REQUEST_LOGGER.undertowRequestFailed (CVE-2019-3888)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-apache-commons-codec | <1.11.0-2.redhat_00001.1.el8ea | 1.11.0-2.redhat_00001.1.el8ea |
redhat/eap7-apache-cxf | <3.2.7-2.redhat_00002.1.el8ea | 3.2.7-2.redhat_00002.1.el8ea |
redhat/eap7-hal-console | <3.0.11-1.Final_redhat_00001.1.el8ea | 3.0.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <5.3.10-1.Final_redhat_00001.1.el8ea | 5.3.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hornetq | <2.4.7-7.Final_redhat_2.1.el8ea | 2.4.7-7.Final_redhat_2.1.el8ea |
redhat/eap7-ironjacamar | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-javassist | <3.23.2-2.GA_redhat_00001.1.el8ea | 3.23.2-2.GA_redhat_00001.1.el8ea |
redhat/eap7-jboss-ejb-client | <4.0.18-1.Final_redhat_00001.1.el8ea | 4.0.18-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-marshalling | <2.0.7-2.Final_redhat_00001.1.el8ea | 2.0.7-2.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-modules | <1.8.8-1.Final_redhat_00001.1.el8ea | 1.8.8-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-openjdk-orb | <8.1.3-1.Final_redhat_00001.1.el8ea | 8.1.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <5.0.9-1.Final_redhat_00001.1.el8ea | 5.0.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-xnio-base | <3.6.6-1.Final_redhat_00001.1.el8ea | 3.6.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jgroups | <4.0.19-1.Final_redhat_00001.1.el8ea | 4.0.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-picketlink-bindings | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-federation | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-resteasy | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-undertow | <2.0.20-1.Final_redhat_00001.1.el8ea | 2.0.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-core | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <7.2.2-2.GA_redhat_00001.1.el8ea | 7.2.2-2.GA_redhat_00001.1.el8ea |
redhat/eap7-wildfly-common | <1.5.1-1.Final_redhat_00001.1.el8ea | 1.5.1-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-discovery | <1.1.2-1.Final_redhat_00001.1.el8ea | 1.1.2-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <1.0.15-1.Final_redhat_00001.1.el8ea | 1.0.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-naming-client | <1.0.10-1.Final_redhat_00001.1.el8ea | 1.0.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-apache-cxf-rt | <3.2.7-2.redhat_00002.1.el8ea | 3.2.7-2.redhat_00002.1.el8ea |
redhat/eap7-apache-cxf-services | <3.2.7-2.redhat_00002.1.el8ea | 3.2.7-2.redhat_00002.1.el8ea |
redhat/eap7-apache-cxf-tools | <3.2.7-2.redhat_00002.1.el8ea | 3.2.7-2.redhat_00002.1.el8ea |
redhat/eap7-hibernate-core | <5.3.10-1.Final_redhat_00001.1.el8ea | 5.3.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-entitymanager | <5.3.10-1.Final_redhat_00001.1.el8ea | 5.3.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-envers | <5.3.10-1.Final_redhat_00001.1.el8ea | 5.3.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-java8 | <5.3.10-1.Final_redhat_00001.1.el8ea | 5.3.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hornetq-commons | <2.4.7-7.Final_redhat_2.1.el8ea | 2.4.7-7.Final_redhat_2.1.el8ea |
redhat/eap7-hornetq-core-client | <2.4.7-7.Final_redhat_2.1.el8ea | 2.4.7-7.Final_redhat_2.1.el8ea |
redhat/eap7-hornetq-jms-client | <2.4.7-7.Final_redhat_2.1.el8ea | 2.4.7-7.Final_redhat_2.1.el8ea |
redhat/eap7-ironjacamar-common-api | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-common-impl | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-common-spi | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-core-api | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-core-impl | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-deployers-common | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-jdbc | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar-validator | <1.4.16-2.Final_redhat_00001.1.el8ea | 1.4.16-2.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-marshalling-river | <2.0.7-2.Final_redhat_00001.1.el8ea | 2.0.7-2.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration-cli | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-core | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap6.4-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.0 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.0-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.1 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.1-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.0 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.0-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.1 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly10.1-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly11.0 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly11.0-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly12.0 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly12.0-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly13.0-server | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly14.0-server | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly8.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly8.2-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly9.0 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-jboss-server-migration-wildfly9.0-to-eap7.2 | <1.3.1-2.Final_redhat_00002.1.el8ea | 1.3.1-2.Final_redhat_00002.1.el8ea |
redhat/eap7-picketlink-api | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-common | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-config | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-idm-api | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-idm-impl | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-idm-simple-schema | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-impl | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-picketlink-wildfly8 | <2.5.5-17.SP12_redhat_00005.1.el8ea | 2.5.5-17.SP12_redhat_00005.1.el8ea |
redhat/eap7-resteasy-atom-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-cdi | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-client-microprofile | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-crypto | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jackson2-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxb-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jaxrs | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jettison-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jose-jwt | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-jsapi | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-binding-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-json-p-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-multipart-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-rxjava2 | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-spring | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-validator-provider | <11-3.6.1-5.SP5_redhat_00001.1.el8ea | 11-3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-resteasy-yaml-provider | <3.6.1-5.SP5_redhat_00001.1.el8ea | 3.6.1-5.SP5_redhat_00001.1.el8ea |
redhat/eap7-weld-core-impl | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-core-jsf | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-ejb | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-jta | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-probe-core | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-weld-web | <3.0.6-1.Final_redhat_00001.1.el8ea | 3.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-discovery-client | <1.1.2-1.Final_redhat_00001.1.el8ea | 1.1.2-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client-common | <1.0.15-1.Final_redhat_00001.1.el8ea | 1.0.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-ejb-client | <1.0.15-1.Final_redhat_00001.1.el8ea | 1.0.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-naming-client | <1.0.15-1.Final_redhat_00001.1.el8ea | 1.0.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-transaction-client | <1.0.15-1.Final_redhat_00001.1.el8ea | 1.0.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-javadocs | <7.2.2-2.GA_redhat_00001.1.el8ea | 7.2.2-2.GA_redhat_00001.1.el8ea |
redhat/eap7-wildfly-modules | <7.2.2-2.GA_redhat_00001.1.el8ea | 7.2.2-2.GA_redhat_00001.1.el8ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.