Lucene search

K
redhatRedHatRHSA-2016:0040
HistoryJan 14, 2016 - 6:31 p.m.

(RHSA-2016:0040) Critical: Red Hat JBoss Operations Network 3.1.2 Hotfix 11 update

2016-01-1418:31:06
access.redhat.com
14

0.018 Low

EPSS

Percentile

88.4%

JBoss Operations Network provides an integrated solution for managing
JBoss middleware, other network infrastructure, and applications built
on Red Hat Enterprise Application Platform (EAP). The Apache Commons
Collections library provides new interfaces, implementations, and
utilities to extend the features of the Java Collections Framework.

It was found that the Apache commons-collections library permitted code
execution when deserializing objects involving a specially constructed
chain of classes. A remote attacker could use this flaw to execute
arbitrary code with the permissions of the application using the
commons-collections library. (CVE-2015-7501)

Further information about this security flaw may be found at:
https://access.redhat.com/solutions/2045023

All users of JBoss Operations Network 3.1.2 as provided from the Red Hat
Customer Portal are advised to apply this update. This patch supersedes
the 3.2.1 Hotfix 10.