Hide Forgot
It was found that HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2022:0400 https://access.redhat.com/errata/RHSA-2022:0400
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2022:0401 https://access.redhat.com/errata/RHSA-2022:0401
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2022:0404 https://access.redhat.com/errata/RHSA-2022:0404
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-20318