RHSA-2020:0310: Important: rh-java-common-xmlrpc security update
Apache XML-RPC is a Java implementation of XML-RPC, a popular protocol that uses XML over HTTP to implement remote procedure calls.<br>Security Fix(es):<br><li> xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response (CVE-2019-17570)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0310?
The severity of RHSA-2020:0310 is considered moderate due to the deserialization vulnerability that can lead to potential exploitation.
How do I fix RHSA-2020:0310?
To fix RHSA-2020:0310, update the affected packages to version 3.1.3-8.17.el7 or 3.1.3-8.17.el6 as appropriate.
What vulnerabilities are addressed in RHSA-2020:0310?
RHSA-2020:0310 addresses the CVE-2019-17570 vulnerability related to the deserialization of server-side exceptions.
Which packages are affected by RHSA-2020:0310?
Affected packages under RHSA-2020:0310 include rh-java-common-xmlrpc, rh-java-common-xmlrpc-client, rh-java-common-xmlrpc-common, among others.
Is RHSA-2020:0310 applicable to all Red Hat systems?
RHSA-2020:0310 applies to specific Red Hat Enterprise Linux versions, particularly those using the affected XML-RPC packages.