First published: Thu Mar 12 2020(Updated: )
This release of Red Hat JBoss Enterprise Application Platform 7.2.7 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.2.6, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.2.7 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> commons-beanutils: apache-commons-beanutils: does not suppresses the class</li> property in PropertyUtilsBean by default (CVE-2019-10086)<br><li> libthrift: thrift: Endless loop when feed with specific input data</li> (CVE-2019-0205)<br><li> libthrift: thrift: Out-of-bounds read related to TJSONProtocol or</li> TSimpleJSONProtocol (CVE-2019-0210)<br><li> xmlsec: xml-security: Apache Santuario potentially loads XML parsing code from</li> an untrusted source (CVE-2019-12400)<br><li> wildfly: The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use (CVE-2019-14887)</li> <li> netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling (CVE-2020-7238)</li> <li> netty: HTTP request smuggling (CVE-2019-20444)</li> <li> netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header (CVE-2019-20445)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-activemq-artemis | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-apache-commons-beanutils | <1.9.4-1.redhat_00002.1.el7ea | 1.9.4-1.redhat_00002.1.el7ea |
redhat/eap7-glassfish-el | <3.0.1-4.b08_redhat_00003.1.el7ea | 3.0.1-4.b08_redhat_00003.1.el7ea |
redhat/eap7-glassfish-jaxb | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <2.3.5-7.SP3_redhat_00005.1.el7ea | 2.3.5-7.SP3_redhat_00005.1.el7ea |
redhat/eap7-hal-console | <3.0.20-1.Final_redhat_00001.1.el7ea | 3.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <5.3.15-1.Final_redhat_00001.1.el7ea | 5.3.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <2.9.10.2-1.redhat_00001.1.el7ea | 2.9.10.2-1.redhat_00001.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-jboss-ejb-client | <4.0.28-1.Final_redhat_00001.1.el7ea | 4.0.28-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting | <5.0.17-1.Final_redhat_00001.1.el7ea | 5.0.17-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-picketlink-bindings | <2.5.5-23.SP12_redhat_00012.1.el7ea | 2.5.5-23.SP12_redhat_00012.1.el7ea |
redhat/eap7-stax2-api | <4.2.0-1.redhat_00001.1.el7ea | 4.2.0-1.redhat_00001.1.el7ea |
redhat/eap7-sun-istack-commons | <3.0.10-1.redhat_00001.1.el7ea | 3.0.10-1.redhat_00001.1.el7ea |
redhat/eap7-thrift | <0.13.0-1.redhat_00002.1.el7ea | 0.13.0-1.redhat_00002.1.el7ea |
redhat/eap7-wildfly | <7.2.7-4.GA_redhat_00004.1.el7ea | 7.2.7-4.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-http-client | <1.0.20-1.Final_redhat_00001.1.el7ea | 1.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-openssl | <1.0.9-2.SP03_redhat_00001.1.el7ea | 1.0.9-2.SP03_redhat_00001.1.el7ea |
redhat/eap7-wildfly-transaction-client | <1.1.9-1.Final_redhat_00001.1.el7ea | 1.1.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-woodstox-core | <6.0.3-1.redhat_00001.1.el7ea | 6.0.3-1.redhat_00001.1.el7ea |
redhat/eap7-xml-security | <2.1.4-1.redhat_00001.1.el7ea | 2.1.4-1.redhat_00001.1.el7ea |
redhat/eap7-activemq-artemis-cli | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-commons | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-core-client | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-dto | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-hornetq-protocol | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-hqclient-protocol | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-jdbc-store | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-jms-client | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-jms-server | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-journal | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-ra | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-selector | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-server | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-service-extensions | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-activemq-artemis-tools | <2.9.0-2.redhat_00009.1.el7ea | 2.9.0-2.redhat_00009.1.el7ea |
redhat/eap7-codemodel | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-glassfish-el-impl | <3.0.1-4.b08_redhat_00003.1.el7ea | 3.0.1-4.b08_redhat_00003.1.el7ea |
redhat/eap7-hibernate-core | <5.3.15-1.Final_redhat_00001.1.el7ea | 5.3.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-entitymanager | <5.3.15-1.Final_redhat_00001.1.el7ea | 5.3.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-envers | <5.3.15-1.Final_redhat_00001.1.el7ea | 5.3.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-java8 | <5.3.15-1.Final_redhat_00001.1.el7ea | 5.3.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-cachestore-jdbc | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-cachestore-remote | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-client-hotrod | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-commons | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-core | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-commons | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-spi | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-v53 | <9.3.8-1.Final_redhat_00001.1.el7ea | 9.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-common-api | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-common-impl | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-common-spi | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-core-api | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-core-impl | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-deployers-common | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-jdbc | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar-validator | <1.4.20-1.Final_redhat_00001.1.el7ea | 1.4.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-istack-commons-runtime | <3.0.10-1.redhat_00001.1.el7ea | 3.0.10-1.redhat_00001.1.el7ea |
redhat/eap7-istack-commons-tools | <3.0.10-1.redhat_00001.1.el7ea | 3.0.10-1.redhat_00001.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java-core | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java-thrift | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-jaxb-jxc | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-jaxb-runtime | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-jaxb-xjc | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration-cli | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-core | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap6.4 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap6.4-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap7.0 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap7.0-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap7.1 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap7.1-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly10.0 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly10.0-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly10.1 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly10.1-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly11.0 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly11.0-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly12.0 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly12.0-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly13.0-server | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly14.0-server | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly8.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly8.2-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly9.0 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-server-migration-wildfly9.0-to-eap7.2 | <1.3.1-8.Final_redhat_00009.1.el7ea | 1.3.1-8.Final_redhat_00009.1.el7ea |
redhat/eap7-picketlink-wildfly8 | <2.5.5-23.SP12_redhat_00012.1.el7ea | 2.5.5-23.SP12_redhat_00012.1.el7ea |
redhat/eap7-relaxng-datatype | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-rngom | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-txw2 | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client-common | <1.0.20-1.Final_redhat_00001.1.el7ea | 1.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-ejb-client | <1.0.20-1.Final_redhat_00001.1.el7ea | 1.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-naming-client | <1.0.20-1.Final_redhat_00001.1.el7ea | 1.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-transaction-client | <1.0.20-1.Final_redhat_00001.1.el7ea | 1.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-java-jdk11 | <7.2.7-4.GA_redhat_00004.1.el7ea | 7.2.7-4.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-java-jdk8 | <7.2.7-4.GA_redhat_00004.1.el7ea | 7.2.7-4.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-javadocs | <7.2.7-4.GA_redhat_00004.1.el7ea | 7.2.7-4.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-modules | <7.2.7-4.GA_redhat_00004.1.el7ea | 7.2.7-4.GA_redhat_00004.1.el7ea |
redhat/eap7-wildfly-openssl-java | <1.0.9-2.SP03_redhat_00001.1.el7ea | 1.0.9-2.SP03_redhat_00001.1.el7ea |
redhat/eap7-xsom | <2.3.3-4.b02_redhat_00001.1.el7ea | 2.3.3-4.b02_redhat_00001.1.el7ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.