RHEL 9 : Red Hat JBoss Enterprise Application Platform 8.1.8 (RHSA-2026:70229)

high Nessus プラグイン ID 348793

概要

リモート Red Hat ホストに 1 つ以上の Red Hat JBoss Enterprise Application Platform 8.1.8 のセキュリティ更新がありません。

説明

リモート Redhat Enterprise Linux 9 ホストに、RHSA-2026:70229 アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

Red Hat JBoss Enterprise Application Platform 8 は、WildFly アプリケーションランタイムをベースにした Java アプリケーション用のプラットフォームです。Red Hat JBoss Enterprise Application Platform 8.1.8 のこのリリースは、Red Hat JBoss Enterprise Application Platform 8.1.7 に置き換わるものとして機能し、バグ修正プログラムと拡張機能が含まれています。このリリースに含まれる最も重要なバグ修正プログラムと拡張機能については、『Red Hat JBoss Enterprise Application Platform 8.1.8 リリースノート』を参照してください。

セキュリティ修正:

* jackson-core: jackson-core:非同期 JSON パーサーの不完全な修正によるサービス拒否 [eap-8.1.z](CVE-2026-68494)

* netty-codec-http2:Netty:SPDY-to-HTTP コーデックでのメモリ枯渇によるサービス拒否 [eap-8.1.z](CVE-2026-56745)

* netty-handler:Netty:OpenSSL クライアントパスの構成ミスによるTLSホスト名検証のバイパス [eap-8.1.z](CVE-2026-62243)

* bcpg-jdk18on:Bouncy Castle for Java:OpenPGP ユーザー属性サブパケット長が際限のないことによるサービス拒否 [eap-8.1.z](CVE-2026-59649)

* jackson-databind: jackson-databind:無視されたプロパティが予期せず変更される可能性があります [eap-8.1.z](CVE-2026-54515)

* jackson-databind:jackson-databind:@JsonUnwrappedプロパティの不適切な処理による権限昇格[eap-8.1.z](CVE-2026-59889)

* netty-codec-dns:netty:無効な形式のドメイン名を持つ DNS Record デコーダーでのメモリリークによるサービス拒否 [eap-8.1.z](CVE-2026-73508)

* jboss-eap.1-runtime-maven-repository.zip:jackson-core:非同期 JSON パーサーの不完全な修正によるサービス拒否 [eap-8.1.z](CVE-2026-68494)

* jboss-eap-runtime-maven-repository.zip:jackson-core:非同期 JSON パーサーの不完全な修正によるサービス拒否 [eap-8.1.z](CVE-2026-68494)

* bcprov-jdk18on:無限の PGP AEAD チャンクサイズが事前認証リソースの枯渇につながります [eap-8.1.z](CVE-2026-3505)

* brace-expansion: brace-expansion:無限の中間配列によるサービス拒否 [eap-8.1.z](CVE-2026-69152)

* netty-codec-http: Netty:netty-codec-http でのメモリ枯渇(展開爆弾)[eap-8.1.z](CVE-2026-59899)

* netty-codec-http:Netty:セキュリティコントロールバイパスにより、NULL 生成元ヘッダーを介した認証されていないリクエストが可能 [eap-8.1.z](CVE-2026-56746)

* netty-codec-http:Netty:SPDY-to-HTTP コーデックでのメモリ枯渇によるサービス拒否 [eap-8.1.z](CVE-2026-56745)

* netty-codec-http:Netty:SPDY SETTINGS フレーム処理によるサービス拒否 [eap-8.1.z](CVE-2026-55831)

* netty-codec-http:Netty:SPDY ヘッダー展開増幅によるサービス拒否 [eap-8.1.z](CVE-2026-55833)

* jackson-databind:jackson-databind:セキュリティバイパスにより任意のコードが実行される可能性があります[eap-8.1.z](CVE-2026-54513)

* jackson-databind: jackson-databind:PolymorphicTypeValidator バイパスによる任意のコードの実行 [eap-8.1.z](CVE-2026-54512)

* undertow-core:オーバーサイズチャンクサイズのビットオーバーラップを介した Undertow:HTTP リクエストスマグリング [eap-8.1.z](CVE-2026-14180)

* artemis-server: artemis-server:channel0 の CORE SUBSCRIBE_TOPOLOGY_V2を介した事前認証トポロジー漏洩 [eap-8.1.z](CVE-2026-49363)

* undertow-websockets-jsr:undertow:任意の @OnMessage メソッドで @ServerEndpoint クラスを持つ websocket エンドポイントでの事前認証 DoS [eap-8.1.z](CVE-2026-15565)

* wildfly-iiop-openjdk:Wildfly:IIOP リスナーでの事前認証のサービス拒否 [eap-8.1.z](CVE-2026-15567)

* cxf-rt-transports-jms:Apache CXF:信頼できない JMS 構成による任意のコードの実行 [eap-8.1.z](CVE-2026-50632)

* cxf-core:Apache CXF:JAXP 堅牢化がないことによる帯域外外部エンティティ解決を介した情報漏洩 [eap-8.1.z](CVE-2026-49875)

* wildfly-elytron-asn1:細工された DER ペイロードを介した WildFly Elytron ASN.1 DERDecoder における際限のないメモリ割り当て [eap-8.1.z](CVE-2026-10832)

* cxf-rt-transports-jms:Apache CXF:信頼できない JMS 構成によるリモートコード実行 [eap-8.1.z](CVE-2026-44417)

* wildfly-elytron-realm-token:EAP の elytron oauth2 でのパラメーターインジェクション [eap-8.1.z](CVE-2026-85511)

* jakarta.faces:mojarra:ui:include での EL インジェクションによる、EAP JSF アプリケーションにおける認証されていない RCE [eap-8.1.z](CVE-2026-46581)

* wildfly-iiop-openjdk:EAP の IIOP NameService に認証がないことが、MITM または DoS につながります [eap-8.1.z](CVE-2026-15563)

* jboss-remoting:jboss-remoting:MessageReader の整数オーバーフローにより、事前認証のサービス拒否が発生します [eap-8.1.z](CVE-2026-15562)

* undertow-core:EAP の Undertow におけるチャンクトレーラーの制限の欠如による OOM [eap-8.1.z](CVE-2026-15561)

* openjdk-orb:EAP の IIOP 経由の認証されていないクラス読み込み [eap-8.1.z](CVE-2026-15560)

* artemis-server:認証の欠如による Artemis セッションハイジャックのApache [eap-8.1.z](CVE-2026-57967)

* wildfly-clustering-infinispan-marshalling:フィルタリングされていない River Unmarshaller を介した Jboss の逆シリアル化 RCE [eap-8.1.z](CVE-2026-15555)

* undertow-core:Undertow:AJP ssl_cert/is_ssl 偽造を介した認証バイパス [eap-8.1.z](CVE-2026-15554)

* jgroups:JGroupsのなりすましによるArtemisクラスタパスワードの漏えい[EAP-8.1.z](CVE-2026-49364)

* artemis-server:artemis コアプロトコルにより、認証されていないキュー作成が許可されます [eap-8.1.z](CVE-2026-49362)

* artemis-server:Red Hat EAP の artemis メッセージングハンドラーは、デフォルトで逆シリアル化を許可します [eap-8.1.z](CVE-2026-86404)

* undertow-core:Undertow:WebSocket permessage-deflate 処理によるサービス拒否 [eap-8.1.z](CVE-2026-5680)

影響、CVSS スコア、謝辞、その他の関連情報を含むセキュリティ問題の詳細については、「参照」セクションに記載されている CVE のページを参照してください。

Tenable は、前述の記述ブロックを Red Hat Enterprise Linux セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

RHEL Red Hat JBoss Enterprise Application Platform 8.1.8パッケージを、RHSA-2026:70229 のガイダンスに従って更新してください。

参考資料

https://access.redhat.com/articles/7137769

https://access.redhat.com/errata/RHSA-2026:70229

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2455350

https://bugzilla.redhat.com/show_bug.cgi?id=2458638

https://bugzilla.redhat.com/show_bug.cgi?id=2477930

https://bugzilla.redhat.com/show_bug.cgi?id=2477945

https://bugzilla.redhat.com/show_bug.cgi?id=2478013

https://bugzilla.redhat.com/show_bug.cgi?id=2480601

https://bugzilla.redhat.com/show_bug.cgi?id=2480637

https://bugzilla.redhat.com/show_bug.cgi?id=2480638

https://bugzilla.redhat.com/show_bug.cgi?id=2480729

https://bugzilla.redhat.com/show_bug.cgi?id=2483131

https://bugzilla.redhat.com/show_bug.cgi?id=2483133

https://bugzilla.redhat.com/show_bug.cgi?id=2483135

https://bugzilla.redhat.com/show_bug.cgi?id=2483136

https://bugzilla.redhat.com/show_bug.cgi?id=2483138

https://bugzilla.redhat.com/show_bug.cgi?id=2483140

https://bugzilla.redhat.com/show_bug.cgi?id=2484703

https://bugzilla.redhat.com/show_bug.cgi?id=2488304

https://bugzilla.redhat.com/show_bug.cgi?id=2488309

https://bugzilla.redhat.com/show_bug.cgi?id=2490628

https://bugzilla.redhat.com/show_bug.cgi?id=2491620

https://bugzilla.redhat.com/show_bug.cgi?id=2492010

https://bugzilla.redhat.com/show_bug.cgi?id=2492015

https://bugzilla.redhat.com/show_bug.cgi?id=2492016

https://bugzilla.redhat.com/show_bug.cgi?id=2492627

https://bugzilla.redhat.com/show_bug.cgi?id=2494771

https://bugzilla.redhat.com/show_bug.cgi?id=2500653

https://bugzilla.redhat.com/show_bug.cgi?id=2503101

https://bugzilla.redhat.com/show_bug.cgi?id=2503103

https://bugzilla.redhat.com/show_bug.cgi?id=2505422

https://bugzilla.redhat.com/show_bug.cgi?id=2505911

https://bugzilla.redhat.com/show_bug.cgi?id=2507482

https://bugzilla.redhat.com/show_bug.cgi?id=2510195

https://bugzilla.redhat.com/show_bug.cgi?id=2510722

https://bugzilla.redhat.com/show_bug.cgi?id=2511026

https://bugzilla.redhat.com/show_bug.cgi?id=2515377

https://bugzilla.redhat.com/show_bug.cgi?id=2521309

https://issues.redhat.com/browse/JBEAP-32314

https://issues.redhat.com/browse/JBEAP-32869

https://issues.redhat.com/browse/JBEAP-33162

https://issues.redhat.com/browse/JBEAP-33185

https://issues.redhat.com/browse/JBEAP-33236

https://issues.redhat.com/browse/JBEAP-33237

https://issues.redhat.com/browse/JBEAP-33288

https://issues.redhat.com/browse/JBEAP-33363

https://issues.redhat.com/browse/JBEAP-33405

https://issues.redhat.com/browse/JBEAP-33409

https://issues.redhat.com/browse/JBEAP-33413

https://issues.redhat.com/browse/JBEAP-33449

https://issues.redhat.com/browse/JBEAP-33459

https://issues.redhat.com/browse/JBEAP-33501

https://issues.redhat.com/browse/JBEAP-33580

https://issues.redhat.com/browse/JBEAP-33616

https://issues.redhat.com/browse/JBEAP-33640

https://issues.redhat.com/browse/JBEAP-33683

https://issues.redhat.com/browse/JBEAP-33848

https://issues.redhat.com/browse/JBEAP-33871

https://issues.redhat.com/browse/JBEAP-33904

https://issues.redhat.com/browse/JBEAP-33925

https://issues.redhat.com/browse/JBEAP-33967

https://issues.redhat.com/browse/JBEAP-33968

https://issues.redhat.com/browse/JBEAP-33973

https://issues.redhat.com/browse/JBEAP-34018

https://issues.redhat.com/browse/JBEAP-34095

https://issues.redhat.com/browse/JBEAP-34096

https://issues.redhat.com/browse/JBEAP-34111

https://issues.redhat.com/browse/JBEAP-34161

https://issues.redhat.com/browse/JBEAP-34222

https://issues.redhat.com/browse/JBEAP-34521

http://www.nessus.org/u?29b6d808

http://www.nessus.org/u?4f7c1c91

http://www.nessus.org/u?f66ce2ca

プラグインの詳細

深刻度: High

ID: 348793

ファイル名: redhat-RHSA-2026-70229.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/9/22

更新日: 2026/9/22

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 6.9

パーセンタイル: 96.81

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Critical

基本値: 10

現状値: 7.8

ベクトル: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-49875

CVSS v3

リスクファクター: Critical

基本値: 9.8

現状値: 8.8

ベクトル: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

リスクファクター: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2026-68494

脆弱性情報

CPE: cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-jmail, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pg, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pkix, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-prov, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-util, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle, p-cpe:/a:redhat:enterprise_linux:eap8-codemodel, p-cpe:/a:redhat:enterprise_linux:eap8-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformat-yaml, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformats-text, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-module-jakarta-xmlbind-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb, p-cpe:/a:redhat:enterprise_linux:eap8-jaxbintros, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-api, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-common-tools, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-jaxws-undertow-httpspi, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-spi, p-cpe:/a:redhat:enterprise_linux:eap8-jsf-impl, p-cpe:/a:redhat:enterprise_linux:eap8-log4j, p-cpe:/a:redhat:enterprise_linux:eap8-neethi, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-nimbus-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap8-parsson, p-cpe:/a:redhat:enterprise_linux:eap8-relaxng-datatype, p-cpe:/a:redhat:enterprise_linux:eap8-rngom, p-cpe:/a:redhat:enterprise_linux:eap8-saaj-impl, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-txw2, p-cpe:/a:redhat:enterprise_linux:eap8-undertow, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-ws-commons-xmlschema, p-cpe:/a:redhat:enterprise_linux:eap8-xml-security, p-cpe:/a:redhat:enterprise_linux:eap8-xsom

必要な KB アイテム: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/9/22

脆弱性公開日: 2026/4/15

参照情報

CVE: CVE-2026-10832, CVE-2026-14180, CVE-2026-15554, CVE-2026-15555, CVE-2026-15560, CVE-2026-15561, CVE-2026-15562, CVE-2026-15563, CVE-2026-15565, CVE-2026-15567, CVE-2026-3505, CVE-2026-44417, CVE-2026-46581, CVE-2026-49362, CVE-2026-49363, CVE-2026-49364, CVE-2026-49875, CVE-2026-50632, CVE-2026-54512, CVE-2026-54513, CVE-2026-54515, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-5680, CVE-2026-57967, CVE-2026-59649, CVE-2026-59889, CVE-2026-59899, CVE-2026-62243, CVE-2026-68494, CVE-2026-69152, CVE-2026-73508, CVE-2026-85511, CVE-2026-86404

CWE: 120, 15, 184, 190, 290, 295, 306, 409, 444, 502, 611, 770, 772, 807, 829, 915, 94

RHSA: 2026:70229