Lucene search

K
redhatRedHatRHSA-2016:0124
HistoryFeb 04, 2016 - 12:00 a.m.

(RHSA-2016:0124) Important: jboss-ec2-eap security and enhancement update for EAP 6.4.6

2016-02-0400:00:00
access.redhat.com
26

EPSS

0.071

Percentile

94.1%

Red Hat JBoss Enterprise Application Platform 6 is a platform for Java EE
applications. It is based on JBoss Application Server 7 and incorporates
multiple open-source projects to provide a complete Java EE platform
solution.

It was found that the Java Standard Tag Library (JSTL) allowed the
processing of untrusted XML documents to utilize external entity
references, which could access resources on the host system and,
potentially, allowing arbitrary code execution. (CVE-2015-0254)

Note: Tag Library users may need to take additional steps after applying
this update. Detailed instructions on the additional steps can be found
here:
https://access.redhat.com/solutions/1584363

Red Hat would like to thank David Jorm of IIX, and the Apache Software
Foundation for reporting the CVE-2015-0254 flaw.

  • The jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise
    Application Platform running on the Amazon Web Services (AWS) Elastic
    Compute Cloud (EC2). With this update, the packages have been updated to
    ensure compatibility with Red Hat JBoss Enterprise Application Platform
    6.4.6.

All users of EAP 6.4.5 jboss-ec2-eap are advised to upgrade to these
updated packages.