First published: Mon Sep 14 2020(Updated: )
Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.<br>This release of Red Hat JBoss Enterprise Application Platform 6.4.23 includes bug fixes and enhancements, which are documented in the Release Notes document listed in the References section.<br>Security Fix(es):<br><li> jbossweb: Incomplete fix of CVE-2020-13935 for WebSocket in JBossWeb could lead to DoS (CVE-2020-14384)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.<br>All users of Red Hat JBoss Enterprise Application Platform 6.4 are advised to upgrade to these updated packages.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el7 | 7.5.31-3.Final_redhat_3.1.ep6.el7 |
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el7 | 7.5.31-3.Final_redhat_3.1.ep6.el7 |
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el6 | 7.5.31-3.Final_redhat_3.1.ep6.el6 |
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el6 | 7.5.31-3.Final_redhat_3.1.ep6.el6 |
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el5 | 7.5.31-3.Final_redhat_3.1.ep6.el5 |
redhat/jbossweb | <7.5.31-3.Final_redhat_3.1.ep6.el5 | 7.5.31-3.Final_redhat_3.1.ep6.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.