Red Hat JBoss Enterprise Application Platform 6 is a platform for Java EE
applications. It is based on JBoss Application Server 7 and incorporates
multiple open-source projects to provide a complete Java EE platform
solution.
It was found that the Java Standard Tag Library (JSTL) allowed the
processing of untrusted XML documents to utilize external entity
references, which could access resources on the host system and,
potentially, allowing arbitrary code execution. (CVE-2015-0254)
Note: Tag Library users may need to take additional steps after applying
this update. Detailed instructions on the additional steps can be found
here:
https://access.redhat.com/solutions/1584363
Red Hat would like to thank David Jorm of IIX, and the Apache Software
Foundation for reporting the CVE-2015-0254 flaw.
All users of EAP 6.4.5 jboss-ec2-eap are advised to upgrade to these
updated packages.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 6 | noarch | jboss-ec2-eap-samples | < 7.5.6-1.Final_redhat_1.ep6.el6 | jboss-ec2-eap-samples-7.5.6-1.Final_redhat_1.ep6.el6.noarch.rpm |
RedHat | 6 | src | jboss-ec2-eap | < 7.5.6-1.Final_redhat_1.ep6.el6 | jboss-ec2-eap-7.5.6-1.Final_redhat_1.ep6.el6.src.rpm |
RedHat | 6 | noarch | jboss-ec2-eap | < 7.5.6-1.Final_redhat_1.ep6.el6 | jboss-ec2-eap-7.5.6-1.Final_redhat_1.ep6.el6.noarch.rpm |