First published: Thu May 04 2023(Updated: )
Red Hat Process Automation Manager is an open source business process management suite that combines process management and decision service management and enables business and IT users to create, manage, validate, and deploy process applications and decision services.<br>This asynchronous security patch is an update to Red Hat Process Automation Manager 7.<br>Security Fixes:<br><li> CXF: Apache CXF: SSRF Vulnerability (CVE-2022-46364)</li> <li> keycloak: path traversal via double URL encoding (CVE-2022-3782)</li> <li> undertow: Infinite loop in SslConduit during close (CVE-2023-1108)</li> <li> commons-text: apache-commons-text: variable interpolation RCE (CVE-2022-42889)</li> <li> jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003)</li> <li> jackson-databind: use of deeply nested arrays (CVE-2022-42004)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.