Lucene search

HistoryMar 31, 2014 - 12:00 a.m.

(RHSA-2014:0343) Moderate: Red Hat JBoss Enterprise Application Platform 6.2.2 update


0.005 Low




Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
applications based on JBoss Application Server 7.

It was found that when JBoss Web processed a series of HTTP requests in
which at least one request contained either multiple content-length
headers, or one content-length header with a chunked transfer-encoding
header, JBoss Web would incorrectly handle the request. A remote attacker
could use this flaw to poison a web cache, perform cross-site scripting
(XSS) attacks, or obtain sensitive information from other requests.

It was found that Java Security Manager permissions configured via a policy
file were not properly applied, causing all deployed applications to be
granted the permission. In certain cases, an
attacker could use this flaw to circumvent expected security measures to
perform actions which would otherwise be restricted. (CVE-2014-0093)

The CVE-2014-0093 issue was discovered by Josef Cacek of the Red Hat JBoss
EAP Quality Engineering team.

This release serves as an update for Red Hat JBoss Enterprise Application
Platform 6.2, and includes bug fixes and enhancements. Documentation for
these changes will be available shortly from the Red Hat JBoss Enterprise
Application Platform 6.2.2 Release Notes, linked to in the References.

All users of Red Hat JBoss Enterprise Application Platform 6.2 on Red Hat
Enterprise Linux 5 are advised to upgrade to these updated packages.
The JBoss server process must be restarted for the update to take effect.