CVE-2019-10202: Critical severity redhat JBoss Enterprise Application Platform vulnerability
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10202?
CVE-2019-10202 is a deserialization vulnerability in Red Hat JBoss Enterprise Application Platform (EAP) that allows remote attackers to execute arbitrary code.
What is the severity of CVE-2019-10202?
The severity of CVE-2019-10202 is high with a CVSS score of 8.1.
Which software is affected by CVE-2019-10202?
The affected software is Red Hat JBoss Enterprise Application Platform (EAP) version 7 with Codehaus 1.9.x implementation.
How can I fix CVE-2019-10202?
To fix CVE-2019-10202, update the affected software to version 1.9.13-9.redhat_00006.1.el6ea for el6, version 1.9.13-9.redhat_00006.1.el7ea for el7, or version 1.9.13-9.redhat_00006.1.el8ea for el8.
Are there any references for CVE-2019-10202?
Yes, you can find more information about CVE-2019-10202 at the following references: 1. [CVE-2017-17485](https://access.redhat.com/security/cve/CVE-2017-17485) 2. [CVE-2017-7525](https://access.redhat.com/security/cve/CVE-2017-7525) 3. [CVE-2017-15095](https://access.redhat.com/security/cve/CVE-2017-15095)