Lucene search

K
redhatRedHatRHSA-2016:1424
HistoryJul 13, 2016 - 7:42 p.m.

(RHSA-2016:1424) Moderate: Red Hat JBoss Fuse/A-MQ 6.2.1 security and bug fix update

2016-07-1319:42:20
access.redhat.com
28

0.002 Low

EPSS

Percentile

64.5%

Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards compliant messaging system that is tailored for use in mission critical applications.

This patch is an update to Red Hat JBoss Fuse 6.2.1 and Red Hat JBoss A-MQ 6.2.1. It includes several bug fixes, which are documented in the readme.txt file included with the patch files.

Security Fix(es):

  • It was reported that the web based administration console does not set the X-Frame-Options header in HTTP responses. This allows the console to be embedded in a frame or iframe which could then be used to cause a user to perform an unintended action in the console. (CVE-2016-0734)

  • It was found that Apache Active MQ administration web console did not validate input correctly when creating a queue. An authenticated attacker could exploit this flaw via cross-site scripting and use it to access sensitive information or further attacks. (CVE-2016-0782)

Refer to the readme.txt file included with the patch files for installation instructions.