Lucene search

K
redhatRedHatRHSA-2014:0885
HistoryJul 15, 2014 - 12:00 a.m.

(RHSA-2014:0885) Important: Red Hat JBoss Enterprise Application Platform 5.2.0 security update

2014-07-1500:00:00
access.redhat.com
11

0.008 Low

EPSS

Percentile

82.2%

Red Hat JBoss Enterprise Application Platform is a platform for Java
applications, which integrates the JBoss Application Server with JBoss
Hibernate and JBoss Seam.

It was found that the implementation of the
org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory() method
provided a DocumentBuilderFactory that would expand entity references.
A remote, unauthenticated attacker could use this flaw to read files
accessible to the user running the application server, and potentially
perform other more advanced XXE attacks. (CVE-2014-3530)

Red Hat would like to thank Alexander Papadakis for reporting this issue.

All users of Red Hat JBoss Enterprise Application Platform 5.2.0 on Red Hat
Enterprise Linux 4, 5, and 6 are advised to upgrade to these updated
packages. The JBoss server process must be restarted for the update to take
effect.

0.008 Low

EPSS

Percentile

82.2%