RHSA-2020:5174: Important: Red Hat JBoss Enterprise Application Platform 7.3.3 security update
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.3.Security Fix(es): hibernate-core: SQL injection vulnerability when both hibernate.usesqlcomments and JPQL String literals are used (CVE-2020-25638)For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5174?
The severity of RHSA-2020:5174 is classified as important.
How do I fix RHSA-2020:5174?
To fix RHSA-2020:5174, apply the latest security update available for Red Hat JBoss Enterprise Application Platform 7.3.
What vulnerabilities does RHSA-2020:5174 address?
RHSA-2020:5174 addresses critical vulnerabilities in hibernate-core within JBoss Enterprise Application Platform 7.
Is RHSA-2020:5174 applicable to earlier versions of JBoss?
RHSA-2020:5174 specifically applies to Red Hat JBoss Enterprise Application Platform 7.3 and may not be applicable to earlier versions.
What is the main impact of not addressing RHSA-2020:5174?
Not addressing RHSA-2020:5174 could lead to potential unauthorized access or data breaches due to the identified vulnerabilities.