Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2023:1627 - Bug Fix Advisory
Issued:
2023-04-04
Updated:
2023-04-04

RHBA-2023:1627 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2023:1405 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.6 for RHEL 8 x86_64

Fixes

  • BZ - 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName
  • BZ - 2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryption implementation
  • BZ - 2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF
  • BZ - 2164494 - CVE-2022-4450 openssl: double free after calling PEM_read_bio_ex

CVEs

  • CVE-2022-4304
  • CVE-2022-4450
  • CVE-2023-0215
  • CVE-2023-0286
  • CVE-2023-0767
  • CVE-2023-23916

References

  • https://access.redhat.com/errata/RHSA-2023:1405
  • https://access.redhat.com/containers

ppc64le

ibm-bamoe/bamoe-kogito-builder-rhel8@sha256:b9fe5260ae3cbbeeffe5b79a7837d52d63bbdbf727993e68ae7ae23e13398407
ibm-bamoe/bamoe-kogito-rhel8-operator@sha256:ca5ad59d07df9cdf3c142ad67dbe6b915023ef16bc0742e3c9c49f97008ab2bb
ibm-bamoe/bamoe-kogito-rhel8-operator-bundle@sha256:9c2b2720544d3ceb91e129094880c15b0f3cf267f43d83f1be3d8bca3df20840
ibm-bamoe/bamoe-kogito-runtime-jvm-rhel8@sha256:25aba45c7c8e8feb18b6cbc8e858f41cea3f6154cb6ac030a5b34a5b81c01fc3

x86_64

ibm-bamoe-tech-preview/bamoe-kogito-runtime-native-rhel8@sha256:12cd770ed46477c92cc6a5697679f1da73c8214d0ebfb0700459cdb0265a607d
ibm-bamoe/bamoe-businesscentral-monitoring-rhel8@sha256:e4fcb5f7d13fad82aa656248a17436a44703c3e39b9ce14e64d68325714eda1b
ibm-bamoe/bamoe-businesscentral-rhel8@sha256:de4e91070a668d2a4d1e9fb3d08d2c861f02a8d05c1657347dce96f416f448c3
ibm-bamoe/bamoe-controller-rhel8@sha256:36ffa2664907db4784f402ed517d3705b3015609efd24756901e62021bfc2ef9
ibm-bamoe/bamoe-dashbuilder-rhel8@sha256:bc440b7e33e320252db66472a973679d68a068ba67c5001b16147dcdff9f5982
ibm-bamoe/bamoe-kieserver-rhel8@sha256:5fadbcfad1117f5ae0d952332340a836a57a27e5f0cc84e05c47979a1b22a09b
ibm-bamoe/bamoe-kogito-builder-rhel8@sha256:07c4e6c16a0801f45933ff74fa955dc29a6d9df0a3e36e5fec52d0fe43ac0009
ibm-bamoe/bamoe-kogito-rhel8-operator@sha256:075003443995eec1615f81a9fa6f7dc33fcf8b2e3364269dbf632b162687495c
ibm-bamoe/bamoe-kogito-rhel8-operator-bundle@sha256:4ebcb2afc93b206ed154ae29369df34ac05941bee7c4642f1bf976012c42bd79
ibm-bamoe/bamoe-kogito-runtime-jvm-rhel8@sha256:aec9311dfe5c67a2cc559fb358b98e90455b4ef0617517556e8fdebaebbb4559
ibm-bamoe/bamoe-operator-bundle@sha256:9bae927b26a83bc922a5425cb8c29f4bd041d931e8099922c166633974f2901c
ibm-bamoe/bamoe-process-migration-rhel8@sha256:ecd0937a9efa122c0f9b7119fe7e93cfca63d6d7b97c46e486c2e8caca71a5ca
ibm-bamoe/bamoe-rhel8-operator@sha256:c083b80f56bed1b7ee7611c4b0a906c664a9b8070621bc77ecebdeccab0ea0f0
ibm-bamoe/bamoe-smartrouter-rhel8@sha256:bdbc4b57b20faabca371e383f8a2e7b522a3594c045418c71532f56e87f591a7

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility