Lucene search

K
redhatRedHatRHSA-2017:0171
HistoryJan 18, 2017 - 6:38 p.m.

(RHSA-2017:0171) Moderate: JBoss Enterprise Application Platform 7.0.4 for RHEL 7

2017-01-1818:38:06
access.redhat.com
18

EPSS

0.005

Percentile

77.1%

This release of Red Hat JBoss Enterprise Application Platform 7.0.4 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.0.3, and includes bug fixes and enhancements, which are documented in the Release Notes, linked to in the References section.

Security Fix(es):

  • An EAP feature to download server log files allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user’s browser to request the log files consuming enough resources that normal server functioning could be impaired. (CVE-2016-8627)

  • It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information. (CVE-2016-7061)

The CVE-2016-8627 issue was discovered by Darran Lofthouse and Brian Stansberry (Red Hat).

EPSS

0.005

Percentile

77.1%