RHSA-2020:5175: Important: Red Hat JBoss Enterprise Application Platform 7.3 security update
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8.<br>Security Fix(es):<br><li> hibernate-core: SQL injection vulnerability when both hibernate.usesqlcomments and JPQL String literals are used (CVE-2020-25638)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5175?
The severity of RHSA-2020:5175 is categorized as moderate.
How do I fix RHSA-2020:5175?
To fix RHSA-2020:5175, upgrade to the specified versions of the affected packages for your Red Hat Enterprise Linux version.
Which Red Hat JBoss packages are affected by RHSA-2020:5175?
The affected packages include eap7-hibernate, eap7-hibernate-core, eap7-hibernate-entitymanager, eap7-hibernate-envers, and eap7-hibernate-java8.
What versions of Red Hat Enterprise Linux are impacted by RHSA-2020:5175?
RHSA-2020:5175 impacts Red Hat Enterprise Linux versions 6, 7, and 8.
Is RHSA-2020:5175 an asynchronous patch?
Yes, RHSA-2020:5175 is identified as an asynchronous patch for Red Hat JBoss Enterprise Application Platform 7.