Lucene search

K
redhatRedHatRHSA-2014:0498
HistoryMay 14, 2014 - 12:00 a.m.

(RHSA-2014:0498) Important: Fuse ESB Enterprise 7.1.0 security update

2014-05-1400:00:00
access.redhat.com
36

0.973 High

EPSS

Percentile

99.9%

Fuse ESB Enterprise is an integration platform based on Apache ServiceMix.

It was found that the Struts 1 ActionForm object allowed access to the
‘class’ parameter, which is directly mapped to the getClass() method.
A remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)

Refer to the readme.txt file included with the patch files for
installation instructions.

All users of Fuse ESB Enterprise 7.1.0 as provided from the Red Hat
Customer Portal are advised to apply this security update.