RHEL 8 : Red Hat JBoss Enterprise Application Platform 7.3.9 security update on RHEL 8 (Important) (RHSA-2021:3468)

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:3468 advisory.

– jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate (CVE-2021-28170)

– apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 (CVE-2021-29425)

– undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS (CVE-2021-3597)

– wildfly-core: Invalid Sensitivity Classification of Vault Expression (CVE-2021-3644)

– undertow: buffer leak on incoming websocket PONG message may lead to DoS (CVE-2021-3690)

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More

Back to Main

Subscribe for the latest news:
%d bloggers like this: