RHSA-2017:2546: Important: Red Hat JBoss BPM Suite 6.4.5 security update
Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes.<br>This release of Red Hat JBoss BPM Suite 6.4.5 serves as a replacement for Red Hat JBoss BPM Suite 6.4.4, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> A deserialization flaw was discovered in the jackson-databind which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. (CVE-2017-7525)</li> <li> A vulnerability was found in Jasypt that would allow an attacker to perform a timing attack on password hash comparison. (CVE-2014-9970)</li> <li> An XXE vulnerability was found in Apache Batik which could allow a remote attacker to retrieve the files on the vulnerable server's filesystem by uploading specially crafted SVG images. The vulnerability could also allow a denial of service condition by performing an amplification attack. (CVE-2017-5662)</li> Red Hat would like to thank Liao Xinxi (NSFOCUS) for reporting CVE-2017-7525.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:2546?
The severity of RHSA-2017:2546 is classified as important.
How do I fix RHSA-2017:2546?
To fix RHSA-2017:2546, you should update your Red Hat JBoss BPM Suite to the latest version as recommended in the advisory.
Which versions are affected by RHSA-2017:2546?
RHSA-2017:2546 affects Red Hat JBoss BPM Suite 6.4.5 and earlier versions.
What are the main issues addressed in RHSA-2017:2546?
RHSA-2017:2546 addresses multiple security vulnerabilities that could allow for remote code execution and denial of service.
Is RHSA-2017:2546 applicable to other Red Hat products?
RHSA-2017:2546 is specifically applicable to Red Hat JBoss BPM Suite and does not affect other Red Hat products.