RHSA-2019:1797: Important: Red Hat JBoss BPM Suite 6.4.12 security update
Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes.<br>This release of Red Hat JBoss BPM Suite 6.4.12 serves as a replacement for Red Hat JBoss BPM Suite 6.4.11, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> jackson-databind: arbitrary code execution in slf4j-ext class (CVE-2018-14718)</li> <li> jackson-databind: improper polymorphic deserialization in openjpa class (CVE-2018-19361)</li> <li> jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (CVE-2018-19360)</li> <li> jackson-databind: improper polymorphic deserialization in jboss-common-core (CVE-2018-19362)</li> <li> jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (CVE-2018-14719)</li> <li> jackson-databind: improper polymorphic deserialization of types from Jodd-db library (CVE-2018-12022)</li> <li> jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver (CVE-2018-12023)</li> <li> jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-15095) (CVE-2017-17485)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:1797?
The severity of RHSA-2019:1797 is categorized as moderate.
How do I fix RHSA-2019:1797?
To fix RHSA-2019:1797, you should update to Red Hat JBoss BPM Suite version 6.4.12 or later.
What software does RHSA-2019:1797 affect?
RHSA-2019:1797 affects Red Hat JBoss BPM Suite versions prior to 6.4.12.
What are the main issues addressed in RHSA-2019:1797?
RHSA-2019:1797 addresses security vulnerabilities that could lead to the potential exposure of sensitive information.
Is there a standalone version of the fix for RHSA-2019:1797?
No, the fix for RHSA-2019:1797 is included in the update package for Red Hat JBoss BPM Suite.