First published: Tue Mar 24 2020(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>Security Fix(es):<br><li> The 'enabled-protocols' value in legacy security is not respected if OpenSSL security provider is in use (CVE-2019-14887) </li> <li> libthrift: thrift: Endless loop when feed with specific input data (CVE-2019-0205)</li> <li> libthrift: thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol (CVE-2019-0210)</li> <li> undertow: AJP File Read/Inclusion Vulnerability (CVE-2020-1745)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-jaegertracing-jaeger-client-java | <0.34.1-1.redhat_00002.1.el8ea | 0.34.1-1.redhat_00002.1.el8ea |
redhat/eap7-thrift | <0.13.0-1.redhat_00002.1.el8ea | 0.13.0-1.redhat_00002.1.el8ea |
redhat/eap7-undertow | <2.0.28-4.SP1_redhat_00002.1.el8ea | 2.0.28-4.SP1_redhat_00002.1.el8ea |
redhat/eap7-wildfly-openssl | <1.0.9-2.SP03_redhat_00001.1.el8ea | 1.0.9-2.SP03_redhat_00001.1.el8ea |
redhat/eap7-jaegertracing-jaeger-client-java-core | <0.34.1-1.redhat_00002.1.el8ea | 0.34.1-1.redhat_00002.1.el8ea |
redhat/eap7-jaegertracing-jaeger-client-java-thrift | <0.34.1-1.redhat_00002.1.el8ea | 0.34.1-1.redhat_00002.1.el8ea |
redhat/eap7-wildfly-openssl-java | <1.0.9-2.SP03_redhat_00001.1.el8ea | 1.0.9-2.SP03_redhat_00001.1.el8ea |
redhat/eap7-jaegertracing-jaeger-client-java | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-thrift | <0.13.0-1.redhat_00002.1.el7ea | 0.13.0-1.redhat_00002.1.el7ea |
redhat/eap7-undertow | <2.0.28-4.SP1_redhat_00002.1.el7ea | 2.0.28-4.SP1_redhat_00002.1.el7ea |
redhat/eap7-wildfly-openssl | <1.0.9-2.SP03_redhat_00001.1.el7ea | 1.0.9-2.SP03_redhat_00001.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java-core | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java-thrift | <0.34.1-1.redhat_00002.1.el7ea | 0.34.1-1.redhat_00002.1.el7ea |
redhat/eap7-wildfly-openssl-java | <1.0.9-2.SP03_redhat_00001.1.el7ea | 1.0.9-2.SP03_redhat_00001.1.el7ea |
redhat/eap7-jaegertracing-jaeger-client-java | <0.34.1-1.redhat_00002.1.el6ea | 0.34.1-1.redhat_00002.1.el6ea |
redhat/eap7-thrift | <0.13.0-1.redhat_00002.1.el6ea | 0.13.0-1.redhat_00002.1.el6ea |
redhat/eap7-undertow | <2.0.28-4.SP1_redhat_00002.1.el6ea | 2.0.28-4.SP1_redhat_00002.1.el6ea |
redhat/eap7-wildfly-openssl | <1.0.9-2.SP03_redhat_00001.1.el6ea | 1.0.9-2.SP03_redhat_00001.1.el6ea |
redhat/eap7-jaegertracing-jaeger-client-java-core | <0.34.1-1.redhat_00002.1.el6ea | 0.34.1-1.redhat_00002.1.el6ea |
redhat/eap7-jaegertracing-jaeger-client-java-thrift | <0.34.1-1.redhat_00002.1.el6ea | 0.34.1-1.redhat_00002.1.el6ea |
redhat/eap7-wildfly-openssl-java | <1.0.9-2.SP03_redhat_00001.1.el6ea | 1.0.9-2.SP03_redhat_00001.1.el6ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.