Oval Definition:oval:com.redhat.rhsa:def:20193067
Revision Date:2019-10-16Version:637
Title:RHSA-2019:3067: jss security update (Important)
Description:Java Security Services (JSS) provides an interface between Java Virtual Machine and Network Security Services (NSS). It supports most of the security standards and encryption technologies supported by NSS including communication through SSL/TLS network protocols. JSS is primarily utilized by the Certificate Server as a part of the Identity Management System.

Security Fix(es):

  • JSS: OCSP policy "Leaf and Chain" implicitly trusts the root certificate (CVE-2019-14823)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-14823
    RHSA-2019:3067
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • jss is earlier than 0:4.4.6-3.el7_7
  • AND jss is signed with Red Hat redhatrelease2 key
  • jss-javadoc is earlier than 0:4.4.6-3.el7_7
  • AND jss-javadoc is signed with Red Hat redhatrelease2 key
  • BACK