First published: Tue Nov 26 2019(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform 7.2.5 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.2.4, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.2.5 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> undertow: HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</li> <li> undertow: HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> undertow: HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> undertow: HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</li> <li> wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default (CVE-2019-14838)</li> <li> wildfly: wildfly-security-manager: security manager authorization bypass (CVE-2019-14843)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-apache-cxf | <3.2.10-1.redhat_00001.1.el6ea | 3.2.10-1.redhat_00001.1.el6ea |
redhat/eap7-byte-buddy | <1.9.11-1.redhat_00002.1.el6ea | 1.9.11-1.redhat_00002.1.el6ea |
redhat/eap7-glassfish-jsf | <2.3.5-5.SP3_redhat_00003.1.el6ea | 2.3.5-5.SP3_redhat_00003.1.el6ea |
redhat/eap7-hal-console | <3.0.17-2.Final_redhat_00001.1.el6ea | 3.0.17-2.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate | <5.3.13-1.Final_redhat_00001.1.el6ea | 5.3.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-genericjms | <2.0.2-1.Final_redhat_00001.1.el6ea | 2.0.2-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-msc | <1.4.11-1.Final_redhat_00001.1.el6ea | 1.4.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting | <5.0.16-2.Final_redhat_00001.1.el6ea | 5.0.16-2.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-xnio-base | <3.7.6-2.SP1_redhat_00001.1.el6ea | 3.7.6-2.SP1_redhat_00001.1.el6ea |
redhat/eap7-picketbox | <5.0.3-6.Final_redhat_00005.1.el6ea | 5.0.3-6.Final_redhat_00005.1.el6ea |
redhat/eap7-picketlink-bindings | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-federation | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-resteasy | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-undertow | <2.0.26-2.SP3_redhat_00001.1.el6ea | 2.0.26-2.SP3_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <7.2.5-4.GA_redhat_00002.1.el6ea | 7.2.5-4.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-elytron | <1.6.5-1.Final_redhat_00001.1.el6ea | 1.6.5-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-elytron-tool | <1.4.4-1.Final_redhat_00001.1.el6ea | 1.4.4-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <1.0.17-1.Final_redhat_00001.1.el6ea | 1.0.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-openssl | <1.0.8-1.Final_redhat_00001.1.el6ea | 1.0.8-1.Final_redhat_00001.1.el6ea |
redhat/eap7-yasson | <1.0.5-1.redhat_00001.1.el6ea | 1.0.5-1.redhat_00001.1.el6ea |
redhat/eap7-apache-cxf-rt | <3.2.10-1.redhat_00001.1.el6ea | 3.2.10-1.redhat_00001.1.el6ea |
redhat/eap7-apache-cxf-services | <3.2.10-1.redhat_00001.1.el6ea | 3.2.10-1.redhat_00001.1.el6ea |
redhat/eap7-apache-cxf-tools | <3.2.10-1.redhat_00001.1.el6ea | 3.2.10-1.redhat_00001.1.el6ea |
redhat/eap7-hibernate-core | <5.3.13-1.Final_redhat_00001.1.el6ea | 5.3.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-entitymanager | <5.3.13-1.Final_redhat_00001.1.el6ea | 5.3.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-envers | <5.3.13-1.Final_redhat_00001.1.el6ea | 5.3.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-java8 | <5.3.13-1.Final_redhat_00001.1.el6ea | 5.3.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-common-api | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-common-impl | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-common-spi | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-core-api | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-core-impl | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-deployers-common | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-jdbc | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar-validator | <1.4.18-1.Final_redhat_00001.1.el6ea | 1.4.18-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration-cli | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-core | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap6.4 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap6.4-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap7.0 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap7.0-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap7.1 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap7.1-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly10.0 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly10.0-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly10.1 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly10.1-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly11.0 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly11.0-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly12.0 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly12.0-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly13.0-server | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly14.0-server | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly8.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly8.2-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly9.0 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-jboss-server-migration-wildfly9.0-to-eap7.2 | <1.3.1-6.Final_redhat_00006.1.el6ea | 1.3.1-6.Final_redhat_00006.1.el6ea |
redhat/eap7-picketbox-infinispan | <5.0.3-6.Final_redhat_00005.1.el6ea | 5.0.3-6.Final_redhat_00005.1.el6ea |
redhat/eap7-picketlink-api | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-common | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-config | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-idm-api | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-idm-impl | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-idm-simple-schema | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-impl | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-picketlink-wildfly8 | <2.5.5-20.SP12_redhat_00009.1.el6ea | 2.5.5-20.SP12_redhat_00009.1.el6ea |
redhat/eap7-resteasy-atom-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-cdi | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-client | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-client-microprofile | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-crypto | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jackson-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jackson2-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jaxb-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jaxrs | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jettison-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jose-jwt | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-jsapi | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-json-binding-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-json-p-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-multipart-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-rxjava2 | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-spring | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-validator-provider | <11-3.6.1-7.SP7_redhat_00001.1.el6ea | 11-3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-resteasy-yaml-provider | <3.6.1-7.SP7_redhat_00001.1.el6ea | 3.6.1-7.SP7_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client-common | <1.0.17-1.Final_redhat_00001.1.el6ea | 1.0.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-ejb-client | <1.0.17-1.Final_redhat_00001.1.el6ea | 1.0.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-naming-client | <1.0.17-1.Final_redhat_00001.1.el6ea | 1.0.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-transaction-client | <1.0.17-1.Final_redhat_00001.1.el6ea | 1.0.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-javadocs | <7.2.5-4.GA_redhat_00002.1.el6ea | 7.2.5-4.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-modules | <7.2.5-4.GA_redhat_00002.1.el6ea | 7.2.5-4.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-openssl-java | <1.0.8-1.Final_redhat_00001.1.el6ea | 1.0.8-1.Final_redhat_00001.1.el6ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.