VDB
RHSA-2017%3A2493
RHSA-2017%3A2493
PUBLISHED
CVSS 7.5 HIGH
Red Hat Security Advisory: Red Hat JBoss Web Server 2 security update
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat7-log4j | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-docs-webapp | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | jbcs-httpd24-openssl-libs | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat6-servlet-2.5-api | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-el-2.1-api | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat7-webapps | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-javadoc | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | jbcs-httpd24-openssl-libs | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-log4j | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-webapps | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat7-javadoc | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat6 | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | jbcs-httpd24-openssl-devel | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-lib | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat6-jsp-2.1-api | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat7-jsp-2.2-api | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat7-jsp-2.2-api | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el6 | tomcat6-maven-devel | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat7-docs-webapp | 0, 0 |
| Red Hat:jboss_enterprise_web_server:2::el7 | tomcat7-maven-devel | 0, 0 |
…and 36 more
Timeline
- Aug 21, 2017 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2017:2493 advisory
- https://access.redhat.com/security/updates/classification/#important article
- https://access.redhat.com/articles/3155411 article
- https://bugzilla.redhat.com/show_bug.cgi?id=1377600 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1384743 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1441205 report
- https://bugzilla.redhat.com/show_bug.cgi?id=1459158 report
- https://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_2493.json advisory
- https://access.redhat.com/security/cve/CVE-2016-6304 report
- https://www.cve.org/CVERecord?id=CVE-2016-6304 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-6304 advisory
- https://www.openssl.org/news/secadv/20160922.txt article
- https://access.redhat.com/security/cve/CVE-2016-8610 report
- https://www.cve.org/CVERecord?id=CVE-2016-8610 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-8610 advisory
- http://security.360.cn/cve/CVE-2016-8610 article
- https://access.redhat.com/security/cve/CVE-2017-5647 report
- https://www.cve.org/CVERecord?id=CVE-2017-5647 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5647 advisory
- https://access.redhat.com/security/cve/CVE-2017-5664 report
…and 5 more