-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Decision Manager 7.10.0 security update
Advisory ID:       RHSA-2021:0603-01
Product:           Red Hat Decision Manager
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0603
Issue date:        2021-02-17
CVE Names:         CVE-2020-9488 CVE-2020-13956 CVE-2020-14338 
                   CVE-2020-25638 
====================================================================
1. Summary:

An update is now available for Red Hat Decision Manager.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Decision Manager is an open source decision management platform
that combines business rules management, complex event processing, Decision
Model & Notation (DMN) execution, and Business Optimizer for solving
planning problems. It automates business decisions and makes that logic
available to the entire business. 

This release of Red Hat Decision Manager 7.10.0 serves as an update to Red
Hat Decision Manager 7.9.1, and includes bug fixes and enhancements, which
are documented in the Release Notes document linked to in the References.

Security Fix(es):

* hibernate-core-kie-server-ee8: hibernate-core: SQL injection
vulnerability when both hibernate.use_sql_comments and JPQL String literals
are used (CVE-2020-25638)

* httpclient: apache-httpclient: incorrect handling of malformed authority
component in request URIs (CVE-2020-13956)

* xercesimpl: wildfly: XML validation manipulation due to incomplete
application of use-grammar-pool-only in xercesImpl (CVE-2020-14338)

* log4j-core: log4j: improper validation of certificate with host mismatch
in SMTP appender (CVE-2020-9488)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For on-premise installations, before applying the update, back up your
existing installation, including all applications, configuration files,
databases and database settings, and so on.

It is recommended to halt the server by stopping the JBoss Application
Server process before installing this update; after installing the update,
restart the server by starting the JBoss Application Server process.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

1831139 - CVE-2020-9488 log4j: improper validation of certificate with host mismatch in SMTP appender
1860054 - CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used
1886587 - CVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIs

5. References:

https://access.redhat.com/security/cve/CVE-2020-9488
https://access.redhat.com/security/cve/CVE-2020-13956
https://access.redhat.com/security/cve/CVE-2020-14338
https://access.redhat.com/security/cve/CVE-2020-25638
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----Version: GnuPG v1

iQIVAwUBYC0c/tzjgjWX9erEAQgwPQ//RNhUtWiZoo1eQIdFmY+FnTigYjNlA39l
yBEOgjab1M5QVVPg00nrBep3Cf3E3IxCghMpHvr8QzhLfqXBLeEZaTQmdMbEul5g
TfHni6K4zkf1plRfT42EhJqIny0FxKd94pXfSuCVNMJFKq+IcMXr8XFWPhy3ygwN
UHVaLQI235WKkFpjOB4gFv/H+OLifp4RzN0a2FQdL4Jgsn8Cy+634FpQJXSYVkg0
/W45zRL6pkB9LPxSAkj69yG5e3kk/cjY9N/9KgVwnmEAdaUp6/BLaLFdDWIoIALf
cKUkeYm2zTfUmawvDn3H3Z23hkvCXyJ9W8rp7Yup779DdEWWeXQzIhX0b0/+uUsO
g5PtRJhlBwHIABC6JY6360GxgyUKihmLasqLUwz2Og8c04NDdvoRjqytZZ5R8EM1
uvV03zeoQFsnD8spLLM5tjoCg98ObMPMV5OaYrlDXnsr4Py27u5iYh46a13zDD1c
ef1HGBOjVKecwFSCfUnvk7KZVQFmyRL417+tN/n7F4jjTEl9C1HF6cGnmHHHpCXV
xEX7ZF8bxeGKp274IlmjZ60V6emIMMCsWpS1iKNuaFC2azBbNU8vl2nlY5nJWsyk
qq/5d0FLJ8El8An4VDd6mq4cs7GaO+BOJL81YSunyCBiPcGBCFjxx9CKDbx4/Y7a
oWs1EUGG6o4=hNTN
-----END PGP SIGNATURE-------RHSA-announce mailing list
RHSA-announce@listman.redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-0603:01 Important: Red Hat Decision Manager 7.10.0 security update

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important

Summary

Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation (DMN) execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business.
This release of Red Hat Decision Manager 7.10.0 serves as an update to Red Hat Decision Manager 7.9.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* hibernate-core-kie-server-ee8: hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used (CVE-2020-25638)
* httpclient: apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)
* xercesimpl: wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl (CVE-2020-14338)
* log4j-core: log4j: improper validation of certificate with host mismatch in SMTP appender (CVE-2020-9488)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For on-premise installations, before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
It is recommended to halt the server by stopping the JBoss Application Server process before installing this update; after installing the update, restart the server by starting the JBoss Application Server process.
The References section of this erratum contains a download link (you must log in to download the update).

References

https://access.redhat.com/security/cve/CVE-2020-9488 https://access.redhat.com/security/cve/CVE-2020-13956 https://access.redhat.com/security/cve/CVE-2020-14338 https://access.redhat.com/security/cve/CVE-2020-25638 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2021:0603-01
Product: Red Hat Decision Manager
Advisory URL: https://access.redhat.com/errata/RHSA-2021:0603
Issued Date: : 2021-02-17
CVE Names: CVE-2020-9488 CVE-2020-13956 CVE-2020-14338 CVE-2020-25638

Topic

An update is now available for Red Hat Decision Manager.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1831139 - CVE-2020-9488 log4j: improper validation of certificate with host mismatch in SMTP appender

1860054 - CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl

1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used

1886587 - CVE-2020-13956 apache-httpclient: incorrect handling of malformed authority component in request URIs


Related News