ID

VAR-202009-0037


CVE

CVE-2020-10687


TITLE

Red Hat Undertow input verification error vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-32367

DESCRIPTION

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. Red Hat Undertow is a Java-based embedded Web server of American Red Hat (Red Hat) Company and the default Web server of Wildfly (Java Application Server). -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Enterprise Application Platform 7.3.2 security update Advisory ID: RHSA-2020:3461-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:3461 Issue date: 2020-08-17 CVE Names: CVE-2019-14900 CVE-2020-1710 CVE-2020-1748 CVE-2020-10672 CVE-2020-10673 CVE-2020-10683 CVE-2020-10687 CVE-2020-10693 CVE-2020-10714 CVE-2020-10718 CVE-2020-10740 CVE-2020-14297 ===================================================================== 1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.3.2 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.1, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.2 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * wildfly: exposed setting of TCCL via the EmbeddedManagedProcess API (CVE-2020-10718) * dom4j: XML External Entity vulnerability in default SAX parser (CVE-2020-10683) * wildfly-elytron: session fixation when using FORM authentication (CVE-2020-10714) * wildfly-undertow: Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests (CVE-2020-10687) * jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10673) * hibernate-core: hibernate: SQL injection issue in Hibernate ORM (CVE-2019-14900) * wildfly: unsafe deserialization in Wildfly Enterprise Java Beans (CVE-2020-10740) * jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution (CVE-2020-10672) * undertow: EAP: field-name is not parsed in accordance to RFC7230 (CVE-2020-1710) * hibernate-validator: Improper input validation in the interpolation of constraint error messages (CVE-2020-10693) * wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain (CVE-2020-1748) * wildfly: Some EJB transaction objects may get accumulated causing Denial of Service (CVE-2020-14297) For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1666499 - CVE-2019-14900 hibernate: SQL injection issue in Hibernate ORM 1694235 - CVE-2020-10683 dom4j: XML External Entity vulnerability in default SAX parser 1785049 - CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests 1793970 - CVE-2020-1710 EAP: field-name is not parsed in accordance to RFC7230 1805501 - CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages 1807707 - CVE-2020-1748 Wildfly: Improper authorization issue in WildFlySecurityManager when using alternative protection domain 1815470 - CVE-2020-10673 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution 1815495 - CVE-2020-10672 jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution 1825714 - CVE-2020-10714 wildfly-elytron: session fixation when using FORM authentication 1828476 - CVE-2020-10718 wildfly: exposed setting of TCCL via the EmbeddedManagedProcess API 1834512 - CVE-2020-10740 wildfly: unsafe deserialization in Wildfly Enterprise Java Beans 1853595 - CVE-2020-14297 wildfly: Some EJB transaction objects may get accumulated causing Denial of Service 6. JIRA issues fixed (https://issues.jboss.org/): JBEAP-18793 - [GSS](7.3.z) Upgrade Hibernate ORM from 5.3.16 to 5.3.17 JBEAP-19095 - [GSS](7.3.z) Upgrade wildfly-http-client from 1.0.20 to 1.0.21 JBEAP-19134 - (7.3.z) Upgrade HAL from 3.2.8.Final-redhat-00001 to 3.2.9.Final JBEAP-19185 - (7.3.z) Upgrade IronJacamar from 1.4.20.Final to 1.4.22.Final JBEAP-19203 - (7.3.z) WFCORE-4850 - Updating mockserver to 5.9.0. Exclusion of dependency from xom.io7m JBEAP-19205 - (7.3.z) Upgrade WildFly Core from 10.1.5.Final-redhat-00001 to 10.1.x JBEAP-19269 - [GSS](7.3.z) Upgrade jboss-logmanager from 2.1.14.Final to 2.1.15.Final JBEAP-19322 - (7.3.z) Upgrade XNIO from 3.7.7 to 3.7.8.SP1 JBEAP-19325 - (7.3.z) Upgrade Infinispan from 9.4.18.Final-redhat-00001 to 9.4.19.Final-redhat-00001 JBEAP-19397 - (7.3.z) Upgrade JSF based on Mojarra 2.3.9.SP09-redhat-00001 to 2.3.9.SP11-redhat-00001 JBEAP-19409 - Tracker bug for the EAP 7.3.2 release for RHEL-6 JBEAP-19529 - (7.3.z) Update PR template to include PR-processor hints. JBEAP-19564 - [GSS](7.3.z) Upgrade jboss-ejb-client from 4.0.31.Final-redhat-00001 to 4.0.33.Final-redhat-00001 JBEAP-19585 - [GSS](7.3.z) Upgrade org.jboss.genericjms from 2.0.4 to 2.0.6 JBEAP-19617 - (7.3.z) Upgrade wildfly-naming-client from 1.0.12.Final-redhat-00001 to 1.0.13.Final-redhat-00001 JBEAP-19619 - (7.3.z) Upgrade JBoss JSF API from 3.0.0.SP02-redhat-00001 to 3.0.0.SP04-redhat-00001 JBEAP-19673 - (7.3.z) [WFCORE] Upgrade WildFly Common to 1.5.2.Final JBEAP-19674 - (7.3.z) [WFCORE] Upgrade galleon and wildfly-galleon-plugins from 4.1.2.Final to 4.2.4.Final JBEAP-19874 - [GSS](7.3.z) Upgrade wildfly-http-client from 1.0.21.Final-redhat-00001 to 1.0.22.Final-redhat-00001 7. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 8. References: https://access.redhat.com/security/cve/CVE-2019-14900 https://access.redhat.com/security/cve/CVE-2020-1710 https://access.redhat.com/security/cve/CVE-2020-1748 https://access.redhat.com/security/cve/CVE-2020-10672 https://access.redhat.com/security/cve/CVE-2020-10673 https://access.redhat.com/security/cve/CVE-2020-10683 https://access.redhat.com/security/cve/CVE-2020-10687 https://access.redhat.com/security/cve/CVE-2020-10693 https://access.redhat.com/security/cve/CVE-2020-10714 https://access.redhat.com/security/cve/CVE-2020-10718 https://access.redhat.com/security/cve/CVE-2020-10740 https://access.redhat.com/security/cve/CVE-2020-14297 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/ https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/ 9. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXzqIS9zjgjWX9erEAQjYNxAAk4rojlcRbfjwu0wlWLTU1MbxQNclVtVh MpQnFzyvJVVXX0lslx7NGxHlRNWRgqI/XC1QDqlHpRs4du5/a2Uj+8c5u+WPQefF QCqOvSntbMli42/I7+fCehLVofx/HkuAVcBoGrIGby1E4rddDljh4bH3r43I7wa5 HN9ki8uFAy8bIAzfXW+RB4rxtnsAABv/VFoH1fWmrXCXE6A6aG+AU86ddty0JQHN JhQp6v/X/3ccCvHYTAO8vlbqIJ4fE86e1+5oRBor+4ZD4mMVzGKm4cf8CMPXsKIB 9dFGo8WHFBgEi4hBbBFtFfaE2DGZ6K4Q7X0IAhiiYJmpPg8NgzGiqVvOAG+/OrBz DE84ZPxZwS1zR82wwIyHP4W5mYIhQTxhtp+E9Klu4gpFIAmK8bVfGf2Ub0HOCS6z sbN1Eiv0SBfWRHBfBkuRTBd0aEcmGRNl4GSXzXtanTf0OhFk/4pxdJPmKDEBFWvg 3dtwFi7+/8JoAch8GKQCo4UoSo6etQu45sUH6Q8ozuxYA72+J9K7cpwp/fVhiYRT nruC+2HDuugrC8UVJ/24E++49omdSXAm+UR9tvkFdVU3IpXLJNWO8s4QbrGC7CN7 Lvg/ukygGhrEEyQ1J9yYSeeNISQWJGOSKj/bgYRAh/AbX/QcZZfus7ppAasNjndn Bk4PSTq9yaw= =ZNiG -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. Description: Red Hat Single Sign-On 7.4 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. Security Fix(es): * jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client (CVE-2020-35510) * bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible (CVE-2020-28052) * wildfly-undertow: undertow: Possible regression in fix for CVE-2020-10687 (CVE-2021-20220) * jboss-ejb-client: wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client (CVE-2021-20250) * guava: local information disclosure via temporary directory created with unsafe permissions (CVE-2020-8908) 4. Bugs fixed (https://bugzilla.redhat.com/): 1905796 - CVE-2020-35510 jboss-remoting: Threads hold up forever in the EJB server by suppressing the ack from an EJB client 1906919 - CVE-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissions 1912881 - CVE-2020-28052 bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible 1923133 - CVE-2021-20220 undertow: Possible regression in fix for CVE-2020-10687 1929479 - CVE-2021-20250 wildfly: Information disclosure due to publicly accessible privileged actions in JBoss EJB Client 6

Trust: 2.16

sources: NVD: CVE-2020-10687 // CNVD: CNVD-2020-32367 // PACKETSTORM: 161831 // PACKETSTORM: 158884 // PACKETSTORM: 158889 // PACKETSTORM: 161821 // PACKETSTORM: 159081 // PACKETSTORM: 161827 // PACKETSTORM: 158916 // PACKETSTORM: 161824

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-32367

AFFECTED PRODUCTS

vendor:redhatmodel:jboss enterprise application platformscope:eqversion:7.3

Trust: 1.0

vendor:redhatmodel:jboss enterprise application platformscope:eqversion:7.2

Trust: 1.0

vendor:redhatmodel:undertowscope:ltversion:2.2.0

Trust: 1.0

vendor:redhatmodel:jboss enterprise application platformscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:single sign-onscope:eqversion: -

Trust: 1.0

vendor:redhatmodel:jboss enterprise application platformscope:eqversion:7.4

Trust: 1.0

vendor:redmodel:hat red hat undertowscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-32367 // NVD: CVE-2020-10687

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-10687
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2020-32367
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202004-1135
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-10687
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

CNVD: CNVD-2020-32367
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-10687
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 2.5
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2020-32367 // CNNVD: CNNVD-202004-1135 // NVD: CVE-2020-10687

PROBLEMTYPE DATA

problemtype:CWE-444

Trust: 1.0

sources: NVD: CVE-2020-10687

THREAT TYPE

remote

Trust: 0.9

sources: PACKETSTORM: 158884 // PACKETSTORM: 158889 // PACKETSTORM: 159081 // CNNVD: CNNVD-202004-1135

TYPE

environmental issue

Trust: 0.6

sources: CNNVD: CNNVD-202004-1135

EXTERNAL IDS

db:NVDid:CVE-2020-10687

Trust: 3.0

db:PACKETSTORMid:161821

Trust: 0.7

db:PACKETSTORMid:158916

Trust: 0.7

db:PACKETSTORMid:161824

Trust: 0.7

db:CNVDid:CNVD-2020-32367

Trust: 0.6

db:AUSCERTid:ESB-2021.2416

Trust: 0.6

db:AUSCERTid:ESB-2021.0922

Trust: 0.6

db:AUSCERTid:ESB-2020.3065

Trust: 0.6

db:AUSCERTid:ESB-2020.2826

Trust: 0.6

db:AUSCERTid:ESB-2020.2837

Trust: 0.6

db:PACKETSTORMid:158891

Trust: 0.6

db:PACKETSTORMid:159083

Trust: 0.6

db:CNNVDid:CNNVD-202004-1135

Trust: 0.6

db:PACKETSTORMid:161831

Trust: 0.1

db:PACKETSTORMid:158884

Trust: 0.1

db:PACKETSTORMid:158889

Trust: 0.1

db:PACKETSTORMid:159081

Trust: 0.1

db:PACKETSTORMid:161827

Trust: 0.1

sources: CNVD: CNVD-2020-32367 // PACKETSTORM: 161831 // PACKETSTORM: 158884 // PACKETSTORM: 158889 // PACKETSTORM: 161821 // PACKETSTORM: 159081 // PACKETSTORM: 161827 // PACKETSTORM: 158916 // PACKETSTORM: 161824 // CNNVD: CNNVD-202004-1135 // NVD: CVE-2020-10687

REFERENCES

url:https://access.redhat.com/security/cve/cve-2020-10687

Trust: 2.0

url:https://security.netapp.com/advisory/ntap-20220210-0015/

Trust: 1.6

url:https://bugzilla.redhat.com/show_bug.cgi?id=1785049

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-10687

Trust: 1.4

url:https://lists.apache.org/thread.html/r6603513ea8afbf6857fd77ca5888ec8385d0af493baa4250e28c351c%40%3cdev.cxf.apache.org%3e

Trust: 1.0

url:https://access.redhat.com/security/team/contact/

Trust: 0.8

url:https://bugzilla.redhat.com/):

Trust: 0.8

url:https://issues.jboss.org/):

Trust: 0.7

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/

Trust: 0.6

url:https://access.redhat.com/articles/11258

Trust: 0.6

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/

Trust: 0.6

url:https://access.redhat.com/security/team/key/

Trust: 0.6

url:https://lists.apache.org/thread.html/r6603513ea8afbf6857fd77ca5888ec8385d0af493baa4250e28c351c@%3cdev.cxf.apache.org%3e

Trust: 0.6

url:https://vigilance.fr/vulnerability/undertow-information-disclosure-via-http-requests-invalid-characters-33091

Trust: 0.6

url:https://packetstormsecurity.com/files/161824/red-hat-security-advisory-2021-0874-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.2416

Trust: 0.6

url:https://packetstormsecurity.com/files/158891/red-hat-security-advisory-2020-3463-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.0922

Trust: 0.6

url:https://packetstormsecurity.com/files/161821/red-hat-security-advisory-2021-0885-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2826/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2837/

Trust: 0.6

url:https://packetstormsecurity.com/files/158916/red-hat-security-advisory-2020-3501-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/159083/red-hat-security-advisory-2020-3642-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.3065/

Trust: 0.6

url:https://access.redhat.com/security/cve/cve-2021-20250

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-28052

Trust: 0.4

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-20220

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-35510

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-35510

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-8908

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-8908

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2021-20220

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-28052

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-20250

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-1710

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10740

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10672

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10693

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10714

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10673

Trust: 0.4

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10683

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10714

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10672

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10683

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10693

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10740

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-1710

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-10718

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10718

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-1748

Trust: 0.4

url:https://access.redhat.com/security/cve/cve-2020-1748

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-10673

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2020-14297

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2020-14297

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-14900

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2019-14900

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2020-14307

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-14307

Trust: 0.2

url:https://access.redhat.com/errata/rhsa-2021:0873

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:3461

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:3462

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=appplatform&downloadtype=securitypatches&version=7.3

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:0885

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-6950

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9547

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-1695

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9546

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9547

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-9548

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-1695

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/html-single/installation_guide/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9548

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-8840

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-9546

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.2/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-8840

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:3637

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-6950

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:0872

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.4/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-10758

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-11612

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-10758

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2020:3501

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-1728

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-1728

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=core.service.rhsso&downloadtype=securitypatches&version=7.4

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-11612

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:0874

Trust: 0.1

sources: CNVD: CNVD-2020-32367 // PACKETSTORM: 161831 // PACKETSTORM: 158884 // PACKETSTORM: 158889 // PACKETSTORM: 161821 // PACKETSTORM: 159081 // PACKETSTORM: 161827 // PACKETSTORM: 158916 // PACKETSTORM: 161824 // CNNVD: CNNVD-202004-1135 // NVD: CVE-2020-10687

CREDITS

Red Hat

Trust: 1.4

sources: PACKETSTORM: 161831 // PACKETSTORM: 158884 // PACKETSTORM: 158889 // PACKETSTORM: 161821 // PACKETSTORM: 159081 // PACKETSTORM: 161827 // PACKETSTORM: 158916 // PACKETSTORM: 161824 // CNNVD: CNNVD-202004-1135

SOURCES

db:CNVDid:CNVD-2020-32367
db:PACKETSTORMid:161831
db:PACKETSTORMid:158884
db:PACKETSTORMid:158889
db:PACKETSTORMid:161821
db:PACKETSTORMid:159081
db:PACKETSTORMid:161827
db:PACKETSTORMid:158916
db:PACKETSTORMid:161824
db:CNNVDid:CNNVD-202004-1135
db:NVDid:CVE-2020-10687

LAST UPDATE DATE

2024-11-20T21:58:06.466000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-32367date:2020-06-11T00:00:00
db:CNNVDid:CNNVD-202004-1135date:2022-03-10T00:00:00
db:NVDid:CVE-2020-10687date:2023-11-07T03:14:12.657

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-32367date:2020-06-11T00:00:00
db:PACKETSTORMid:161831date:2021-03-17T14:18:36
db:PACKETSTORMid:158884date:2020-08-17T17:34:41
db:PACKETSTORMid:158889date:2020-08-17T17:43:07
db:PACKETSTORMid:161821date:2021-03-16T14:24:39
db:PACKETSTORMid:159081date:2020-09-07T16:38:23
db:PACKETSTORMid:161827date:2021-03-17T14:14:51
db:PACKETSTORMid:158916date:2020-08-19T16:44:13
db:PACKETSTORMid:161824date:2021-03-17T14:09:45
db:CNNVDid:CNNVD-202004-1135date:2020-04-15T00:00:00
db:NVDid:CVE-2020-10687date:2020-09-23T13:15:15.157