First published: Mon Apr 11 2022(Updated: )
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform 7.4.4 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.3 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.4 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305)</li> <li> log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307)</li> <li> log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104)</li> <li> log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)</li> <li> log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228) (CVE-2021-45046)</li> <li> log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern (CVE-2021-45105)</li> <li> log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-activemq-artemis | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-ecj | <3.26.0-1.redhat_00002.1.el7ea | 3.26.0-1.redhat_00002.1.el7ea |
redhat/eap7-hal-console | <3.3.9-1.Final_redhat_00001.1.el7ea | 3.3.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <5.3.25-1.Final_redhat_00002.1.el7ea | 5.3.25-1.Final_redhat_00002.1.el7ea |
redhat/eap7-infinispan | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <1.10.0-15.Final_redhat_00014.1.el7ea | 1.10.0-15.Final_redhat_00014.1.el7ea |
redhat/eap7-jboss-vfs | <3.2.16-1.Final_redhat_00001.1.el7ea | 3.2.16-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-xnio-base | <3.8.6-1.Final_redhat_00001.1.el7ea | 3.8.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jbossws-cxf | <5.4.4-1.Final_redhat_00001.1.el7ea | 5.4.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-log4j | <2.17.1-1.redhat_00001.1.el7ea | 2.17.1-1.redhat_00001.1.el7ea |
redhat/eap7-narayana | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-objectweb-asm | <9.1.0-1.redhat_00002.1.el7ea | 9.1.0-1.redhat_00002.1.el7ea |
redhat/eap7-undertow | <2.2.16-1.Final_redhat_00001.1.el7ea | 2.2.16-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <7.4.4-3.GA_redhat_00011.1.el7ea | 7.4.4-3.GA_redhat_00011.1.el7ea |
redhat/eap7-wildfly-elytron | <1.15.11-1.Final_redhat_00002.1.el7ea | 1.15.11-1.Final_redhat_00002.1.el7ea |
redhat/eap7-wildfly-openssl | <2.2.0-3.Final_redhat_00002.1.el7ea | 2.2.0-3.Final_redhat_00002.1.el7ea |
redhat/eap7-xom | <1.3.7-1.redhat_00001.1.el7ea | 1.3.7-1.redhat_00001.1.el7ea |
redhat/eap7-yasson | <1.0.10-1.redhat_00001.1.el7ea | 1.0.10-1.redhat_00001.1.el7ea |
redhat/eap7-activemq-artemis-cli | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-commons | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-core-client | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-dto | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-hornetq-protocol | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-hqclient-protocol | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-jdbc-store | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-jms-client | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-jms-server | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-journal | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-ra | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-selector | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-server | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-service-extensions | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-activemq-artemis-tools | <2.16.0-7.redhat_00034.1.el7ea | 2.16.0-7.redhat_00034.1.el7ea |
redhat/eap7-hibernate-core | <5.3.25-1.Final_redhat_00002.1.el7ea | 5.3.25-1.Final_redhat_00002.1.el7ea |
redhat/eap7-hibernate-entitymanager | <5.3.25-1.Final_redhat_00002.1.el7ea | 5.3.25-1.Final_redhat_00002.1.el7ea |
redhat/eap7-hibernate-envers | <5.3.25-1.Final_redhat_00002.1.el7ea | 5.3.25-1.Final_redhat_00002.1.el7ea |
redhat/eap7-hibernate-java8 | <5.3.25-1.Final_redhat_00002.1.el7ea | 5.3.25-1.Final_redhat_00002.1.el7ea |
redhat/eap7-infinispan-cachestore-jdbc | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-cachestore-remote | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-client-hotrod | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-commons | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-component-annotations | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-core | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-commons | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-spi | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan-hibernate-cache-v53 | <11.0.15-1.Final_redhat_00001.1.el7ea | 11.0.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration-cli | <1.10.0-15.Final_redhat_00014.1.el7ea | 1.10.0-15.Final_redhat_00014.1.el7ea |
redhat/eap7-jboss-server-migration-core | <1.10.0-15.Final_redhat_00014.1.el7ea | 1.10.0-15.Final_redhat_00014.1.el7ea |
redhat/eap7-narayana-compensations | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-jbosstxbridge | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-jbossxts | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-jts-idlj | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-jts-integration | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-restat-api | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-restat-bridge | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-restat-integration | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-restat-util | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-narayana-txframework | <5.11.4-1.Final_redhat_00001.1.el7ea | 5.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-elytron-tool | <1.15.11-1.Final_redhat_00002.1.el7ea | 1.15.11-1.Final_redhat_00002.1.el7ea |
redhat/eap7-wildfly-java-jdk11 | <7.4.4-3.GA_redhat_00011.1.el7ea | 7.4.4-3.GA_redhat_00011.1.el7ea |
redhat/eap7-wildfly-java-jdk8 | <7.4.4-3.GA_redhat_00011.1.el7ea | 7.4.4-3.GA_redhat_00011.1.el7ea |
redhat/eap7-wildfly-javadocs | <7.4.4-3.GA_redhat_00011.1.el7ea | 7.4.4-3.GA_redhat_00011.1.el7ea |
redhat/eap7-wildfly-modules | <7.4.4-3.GA_redhat_00011.1.el7ea | 7.4.4-3.GA_redhat_00011.1.el7ea |
redhat/eap7-wildfly-openssl-java | <2.2.0-3.Final_redhat_00002.1.el7ea | 2.2.0-3.Final_redhat_00002.1.el7ea |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1296 is classified as moderate.
To fix RHSA-2022:1296, update the affected packages to the specified remedial versions provided by Red Hat.
RHSA-2022:1296 affects multiple packages including eap7-activemq-artemis, eap7-hibernate, and eap7-wildfly among others.
No, RHSA-2022:1296 is not classified as a critical vulnerability, but it should still be addressed promptly.
RHSA-2022:1296 was released on May 10, 2022.