Lucene search

K
redhatRedHatRHSA-2016:1346
HistoryJun 27, 2016 - 9:02 p.m.

(RHSA-2016:1346) Critical: Red Hat JBoss Data Virtualization security and bug fix update

2016-06-2721:02:25
access.redhat.com
8

0.007 Low

EPSS

Percentile

79.5%

Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems - such as multiple databases, XML files, and even Hadoop systems - appear as a set of tables in a local database.

Security Fix(es):

  • It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks. (CVE-2016-2141)

This issue was discovered by Dennis Reed (Red Hat).