Lucene search

K
redhatRedHatRHSA-2016:1135
HistoryMay 26, 2016 - 7:19 p.m.

(RHSA-2016:1135) Important: Red Hat JBoss Data Virtualization security and bug fix update

2016-05-2619:19:46
access.redhat.com
21

0.118 Low

EPSS

Percentile

95.4%

Red Hat JBoss Data Virtualization is a lean data integration solution that
provides easy, real-time, and unified data access across disparate sources
to multiple applications and users. JBoss Data Virtualization makes data
spread across physically distinct systems - such as multiple databases, XML
files, and even Hadoop systems - appear as a set of tables in a local
database.

Security Fix(es):

  • A deserialization flaw allowing remote code execution was found in the BeanShell library. If BeanShell was on the classpath, it could permit code execution if another part of the application deserialized objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the BeanShell library. (CVE-2016-2510)

  • A denial of service flaw was found in the way the HSLFSlideShow class implementation in Apache POI handled certain PPT files. A remote attacker could submit a specially crafted PPT file that would cause Apache POI to hang indefinitely. (CVE-2014-9527)

All users of Red Hat JBoss Data Virtualization 6.2.0 as provided from the
Red Hat Customer Portal are advised to apply this update.