Lucene search

K
redhatRedHatRHSA-2011:1822
HistoryDec 14, 2011 - 12:00 a.m.

(RHSA-2011:1822) Moderate: JBoss Enterprise Portal Platform 5.2.0 update

2011-12-1400:00:00
access.redhat.com
14

0.022 Low

EPSS

Percentile

89.6%

JBoss Enterprise Portal Platform is the open source implementation of the
Java EE suite of services and Portal services running atop JBoss Enterprise
Application Platform. It comprises a set of offerings for enterprise
customers who are looking for pre-configured profiles of JBoss Enterprise
Middleware components that have been tested and certified together to
provide an integrated experience.

This release of JBoss Enterprise Portal Platform 5.2.0 serves as a
replacement for JBoss Enterprise Portal Platform 5.1.1, and includes bug
fixes and enhancements. Refer to the JBoss Enterprise Portal Platform 5.2.0
Release Notes for information on the most significant of these changes. The
Release Notes will be available shortly from
https://docs.redhat.com/docs/en-US/index.html

The following security issues are also fixed with this release:

Multiple cross-site scripting (XSS) flaws were found in JBoss Enterprise
Portal Platform. If a remote attacker could trick a user, who was logged
into the portal, into visiting a specially-crafted URL, it would lead to
arbitrary web script execution in the context of the user’s portal
session. (CVE-2011-4580)

It was found that the login page of JBoss Enterprise Portal Platform could
be used to perform open URL redirects. A remote attacker could use this
flaw to redirect users to arbitrary websites and conduct phishing attacks
via a URL passed in the initialURI parameter. (CVE-2011-2941)

It was found that the invoker servlets, deployed by default via
httpha-invoker, only performed access control on the HTTP GET and POST
methods, allowing remote attackers to make unauthenticated requests by
using different HTTP methods. Due to the second layer of authentication
provided by a security interceptor, this issue is not exploitable on
default installations unless an administrator has misconfigured the
security interceptor or disabled it. (CVE-2011-4085)

Red Hat would like to thank Christopher Hartley of The Ohio State
University for reporting the CVE-2011-2941 issue.

Warning: Before applying this update, back up all applications deployed on
JBoss Enterprise Portal Platform, along with all customized configuration
files.

All users of JBoss Enterprise Portal Platform 5.1.1 as provided from the
Red Hat Customer Portal are advised to upgrade to JBoss Enterprise Portal
Platform 5.2.0.

0.022 Low

EPSS

Percentile

89.6%