Lucene search

K
redhatRedHatRHSA-2017:0248
HistoryFeb 02, 2017 - 8:26 p.m.

(RHSA-2017:0248) Moderate: Red Hat JBoss BRMS security update

2017-02-0220:26:59
access.redhat.com
17

0.003 Low

EPSS

Percentile

71.2%

Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.

This release of Red Hat JBoss BRMS 6.4.1 serves as a replacement for Red Hat JBoss BRMS 6.4.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • It was found that the parsing of XMP and other XML formats in PDF by Apache PDFBox would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks. (CVE-2016-2175)

  • It was found that the parsing of OOXML, XMP in PDF, and some other file formats by Apache Tika would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks. (CVE-2016-4434)

  • It was discovered that JBoss BRMS 6 and BPM Suite 6 are not setting HttpOnly flags on sensitive cookies. Remote attackers can access these cookies by using client-side scripts, usually through XSS. Please note that on IBM WebSphere the HttpOnly flag cannot be set by deployed applications, it needs to be configured directly on WAS console. (CVE-2016-6344)

The CVE-2016-6344 issue was discovered by Jeremy Choi (Red Hat Product Security Team).