Lucene search

K
redhatRedHatRHSA-2014:0884
HistoryJul 15, 2014 - 5:10 p.m.

(RHSA-2014:0884) Important: Red Hat JBoss Enterprise Application Platform 6.2.4 security update

2014-07-1517:10:54
access.redhat.com
12

0.008 Low

EPSS

Percentile

82.2%

Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
applications based on JBoss Application Server 7.

It was found that the implementation of the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory() method
provided a DocumentBuilderFactory that would expand entity references.
A remote, unauthenticated attacker could use this flaw to read files
accessible to the user running the application server, and potentially
perform other more advanced XXE attacks. (CVE-2014-3530)

Red Hat would like to thank Alexander Papadakis for reporting this issue.

All users of Red Hat JBoss Enterprise Application Platform 6.2.4 as
provided from the Red Hat Customer Portal are advised to apply this update.
The JBoss server process must be restarted for the update to take effect.

0.008 Low

EPSS

Percentile

82.2%