RHSA-2017:2477: Important: Red Hat JBoss Data Virtualization 6.3 Update 7 security update
Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems - such as multiple databases, XML files, and even Hadoop systems - appear as a set of tables in a local database.This release of Red Hat JBoss Data Virtualization 6.3 Update 7 serves as a replacement for Red Hat JBoss Data Virtualization 6.3 Update 6, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. (CVE-2017-7525) A vulnerability was discovered in Apache Thrift client libraries that allows remote, authenticated attackers to cause an infinite recursion via vectors involving the skip function; resulting in a denial of service (DoS) condition. (CVE-2015-3254) A denial of service vulnerability was discovered in ZooKeeper which allows an attacker to dramatically increase CPU utilization by abusing "wchp/wchc" commands, leading to the server being unable to serve legitimate requests. (CVE-2017-5637) Red Hat would like to thank Liao Xinxi (NSFOCUS) for reporting CVE-2017-7525.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:2477?
The severity of RHSA-2017:2477 is classified as moderate.
How do I fix RHSA-2017:2477?
To fix RHSA-2017:2477, you should update the affected Red Hat JBoss Data Virtualization package to the latest version.
What are the potential impacts of RHSA-2017:2477?
The impacts of RHSA-2017:2477 may include exposure to vulnerabilities that could lead to unauthorized access or data compromise.
Which versions of Red Hat JBoss Data Virtualization are affected by RHSA-2017:2477?
RHSA-2017:2477 affects specific versions of Red Hat JBoss Data Virtualization, details of which can be found in the advisory.
Is there a workaround for RHSA-2017:2477 if I cannot apply the fix?
No documented workaround is available for RHSA-2017:2477; applying the recommended updates is the best mitigation.