-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Open Liberty 20.0.0.2 Runtime security update
Advisory ID:       RHSA-2020:0556-01
Product:           Open Liberty
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:0556
Issue date:        2020-02-19
====================================================================
1. Summary:

Open Liberty 20.0.0.2 Runtime is now available from the Customer Portal.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

This release of Open Liberty 20.0.0.2 serves as a replacement for Open
Liberty 20.0.0.1 and includes security fixes, bug fixes, and enhancements.
For specific information about this release, see links in the References
section.

Security Fix(es):

* WebSphere Application Server is vulnerable to a denial of service
(CVE-2019-4720)

* Vulnerability in Apache CXF affects WebSphere Application Server
(CVE-2019-12406)

For more details about the security issue(s), see the IBM Security Bulletin
links for each CVE, listed in the References section.

3. Solution:

Before applying the update, back up your existing installation, including
all applications, configuration files, databases and database settings, and
so on.

The References section of this erratum contains a download link (you must
log in to download the update).

4. JIRA issues fixed (https://issues.redhat.com/plugins/servlet/samlsso

IBMRT-18 - Include open liberty 20.0.0.2 into RedHat runtimes

5. References:

https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=open.liberty&version=20.0.0.2
https://www.ibm.com/support/pages/security-bulletin-websphere-application-server-vulnerable-denial-service-cve-2019-4720
https://www.ibm.com/support/pages/security-bulletin-vulnerability-apache-cxf-affects-websphere-application-server-cve-2019-12406
https://access.redhat.com/articles/4544981
https://access.redhat.com/documentation/en-us/open_liberty/2020/

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXk2gatzjgjWX9erEAQg7jg/8CB033jhY7zpIMHoBxWnzyz3+ZcSDgt3z
idlQqzZXxwe9jbGapGAyioebsEuAAPTJO8w0TTPqyVdq4vPWmvk0iFnY0odIGwvR
/uCB3Jkzr07lvEL8N6YAw71hljzvhAoQ99aXgDc8xUHOuViGsLHh9pEvYOsGTSLM
aIVen7efAgKb5nuuURZhNJLXjdm8S7lAOiIzg/RbbN/qfKcKQpR0NMxW5LvTyzBX
Jvbyw8+Fgx2svocQpVBUKJSQRK79i4BVkSVOtjKUE2graeM1gkNn6y3AI6jLpdjK
4fdLwLIH5bzmerQTexIKyZjdL2t0eyZHd0loDtDE3ZS5YMPFcYyL+NmzWXpFs4MY
VJGzNyGdN9IQLNVZNcJ8GDupnbt0taBYsv5o615b4NU2UGFwedbdNmf3N03EZE0U
AHFawraRRqqLQWxcQh0b77ixirwJLEvcteGkrMXKVQ+O2PrZ0MbvIR+8NQIRlL3l
8jH0fuB3ovfHgzhreocLVf2CKf19Xn9gFiVHa4pwVmdtsK29CZZHPp2qNpE6ygyH
zib7jcUAXo8jsTBvUUH/mRAF+oeB/zbw8zaXm4shkJ2k/oscO9I5Kmn6vZe6V868
HJ6/fthYCZlokx6dSbXOLadF4yP8AO+onqlPlNueYKgzhDRSEiCfwLs2oDOhOsus
JC5TwLoOGo4=8N//
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-0556:01 Important: Open Liberty 20.0.0.2 Runtime security

Open Liberty 20.0.0.2 Runtime is now available from the Customer Portal

Summary

This release of Open Liberty 20.0.0.2 serves as a replacement for Open Liberty 20.0.0.1 and includes security fixes, bug fixes, and enhancements. For specific information about this release, see links in the References section.
Security Fix(es):
* WebSphere Application Server is vulnerable to a denial of service (CVE-2019-4720)
* Vulnerability in Apache CXF affects WebSphere Application Server (CVE-2019-12406)
For more details about the security issue(s), see the IBM Security Bulletin links for each CVE, listed in the References section.



Summary


Solution

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
The References section of this erratum contains a download link (you must log in to download the update).
4. JIRA issues fixed (https://issues.redhat.com/plugins/servlet/samlsso
IBMRT-18 - Include open liberty 20.0.0.2 into RedHat runtimes

References

https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=open.liberty&version=20.0.0.2 https://www.ibm.com/support/pages/security-bulletin-websphere-application-server-vulnerable-denial-service-cve-2019-4720 https://www.ibm.com/support/pages/security-bulletin-vulnerability-apache-cxf-affects-websphere-application-server-cve-2019-12406 https://access.redhat.com/articles/4544981 https://access.redhat.com/documentation/en-us/open_liberty/2020/

Package List


Severity
Advisory ID: RHSA-2020:0556-01
Product: Open Liberty
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0556
Issued Date: : 2020-02-19

Topic

Open Liberty 20.0.0.2 Runtime is now available from the Customer Portal.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed


Related News