RHSA-2015:1009: Important: Red Hat JBoss Portal 6.2.0 update
This release of Red Hat JBoss Portal 6.2.0 serves as a replacement forRed Hat JBoss BPM Suite 6.1.1, and includes bug fixes and enhancements.Refer to the Red Hat JBoss BPM Suite 6.2.0 Release Notes for information onthe most significant of these changes. The Release Notes are available athttps://access.redhat.com/documentation/en-US/RedHatJBossPortal/ The following security issues are also fixed with this release,descriptions of which can be found on the respective CVE pages linked inthe References section.CVE-2012-6153 Apache HttpComponents client / Apache CXF: SSL hostname verification bypassCVE-2013-1624 bouncycastle: TLS CBC padding timing attackCVE-2013-2133 JBoss WS: EJB3 role restrictions are not applied to jaxwshandlersCVE-2013-4286 JBossWeb: multiple content-length header poisoning flawsCVE-2013-5855 Mojarra JSF2: XSS due to insufficient escaping ofuser-supplied content in outputText tags and EL expressionsCVE-2013-7285 XStream: remote code execution due to insecure XMLdeserializationCVE-2014-0005 PicketBox/JBossSX: Security domain authenticationconfiguration modifiable by applicationCVE-2014-0018 JBoss AS Server: Unchecked access to MSC Service Registryunder JSMCVE-2014-0034 Apache CXF: The SecurityTokenService accepts certain invalidSAML Tokens as validCVE-2014-0035 Apache CXF: UsernameTokens are sent in plaintext with aSymmetric EncryptBeforeSigning policyCVE-2014-0050 JBossWeb: denial of service due to too-small buffer size usedbt MultipartStreamCVE-2014-0058 Red Hat JBoss EAP 6: Plain text password loggingCVE-2014-0059 PicketBox/JBossSX: World readable audit.log fileCVE-2014-0075 JBossWeb: Limited DoS in chunked transfer encoding inputfilterCVE-2014-0086 JBoss RichFaces: remote denial of service via memoryexhaustionCVE-2014-0093 Red Hat JBoss EAP 6: JSM policy not respected by deployedapplicationsCVE-2014-0096 JBossWeb: XXE vulnerability via user supplied XSLTsCVE-2014-0099 JBossWeb: Request smuggling via malicious content lengthheaderCVE-2014-0107 Xalan-Java: insufficient constraints in secure processingfeature (oCERT-2014-002)CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could causeOOM errorsCVE-2014-0110 Apache CXF: Large invalid content fills temporary spaceCVE-2014-0119 JBossWeb: XML parser hijack by malicious web applicationCVE-2014-0193 Netty: DoS via memory exhaustion during data aggregationCVE-2014-0227 JBossWeb: Limited DoS in chunked transfer encoding inputfilterCVE-2014-0245 GateIn WSRP: Information disclosure via unsafe concurrencyhandling in interceptorCVE-2014-3472 JBoss AS Controller: Invalid EJB caller role checkCVE-2014-3481 JBoss AS JAX RS Integration: Information disclosure via XMLXXECVE-2014-3490 RESTEasy: XXE via parameter entitiesCVE-2014-3530 PicketLink: XXE via insecure DocumentBuilderFactory usageCVE-2014-3574 Apache POI: entity expansion (billion laughs) flawCVE-2014-3529 Apache POI: XXE flawCVE-2014-3577 Apache HttpComponents incomplete fix for CVE-2012-6153CVE-2014-3586 JBoss AS CLI: Insecure default permissions on history fileCVE-2014-4172 Cas-client: Bypass of security constraints via URL parameterinjectionRed Hat would like to thank James Roper of Typesafe for reportingCVE-2014-0193, CA Technologies for reporting CVE-2014-3472, and AlexanderPapadakis for reporting CVE-2014-3530. The CVE-2013-2133 issue wasdiscovered by Richard Opalka and Arun Neelicattu of Red Hat, theCVE-2014-0005 issue was discovered by Josef Cacek of the Red Hat JBoss EAPQuality Engineering team, the CVE-2014-0018 issue was discovered by StuartDouglas of Red Hat, the CVE-2014-3481 issue was discovered by the Red HatJBoss Enterprise Application Platform QE team, the CVE-2014-0075 andCVE-2014-3490 issues were discovered by David Jorm of Red Hat ProductSecurity, and the CVE-2014-0093 issue was discovered by Josef Cacek of theRed Hat JBoss EAP Quality Engineering team.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2015:1009?
The severity level of RHSA-2015:1009 is classified as important.
How do I fix RHSA-2015:1009?
To fix RHSA-2015:1009, upgrade to Red Hat JBoss Portal version 6.2.0 or later.
What vulnerabilities are addressed in RHSA-2015:1009?
RHSA-2015:1009 addresses multiple bug fixes and enhancements from previous versions of Red Hat JBoss Portal.
What versions are affected by RHSA-2015:1009?
RHSA-2015:1009 affects Red Hat JBoss Portal 6.1.1 and earlier versions.
Is there a workaround for RHSA-2015:1009?
There are no known workarounds for RHSA-2015:1009; applying the update is recommended.