First published: Thu Jun 18 2020(Updated: )
This is an asynchronous patch for Red Hat Fuse 7.6.0 on EAP, and includes the following security fix:<br><li> commons-beanutils: apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)</li> To completely fix this CVE, EAP 7.2.7 or later must be applied to the system in addition to this Fuse on EAP patch. <br>For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Fuse | ||
Red Hat JBoss EAP | >=7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:2619 is classified as important.
To fix RHSA-2020:2619, update Red Hat Fuse to the latest version that includes the asynchronous patch.
RHSA-2020:2619 addresses the CVE-2019-10086 vulnerability related to commons-beanutils.
RHSA-2020:2619 specifically affects Red Hat Fuse 7.6.0 on EAP.
Yes, RHSA-2020:2619 is an asynchronous patch for addressing a specific security issue.