Lucene search

K
redhatRedHatRHSA-2017:3354
HistoryNov 30, 2017 - 4:29 p.m.

(RHSA-2017:3354) Moderate: Red Hat JBoss BRMS 6.4.7 security update

2017-11-3016:29:58
access.redhat.com
19

EPSS

0.045

Percentile

92.5%

Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.

This release of Red Hat JBoss BRMS 6.4.7 serves as a replacement for Red Hat JBoss BRMS 6.4.6, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • A denial of service vulnerability was discovered in ZooKeeper which allows an attacker to dramatically increase CPU utilization by abusing “wchp/wchc” commands, leading to the server being unable to serve legitimate requests. (CVE-2017-5637)

  • It was discovered that the XmlUtils class in jbpmmigration performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user running the application server and, potentially, perform other more advanced XML eXternal Entity (XXE) attacks. (CVE-2017-7545)

Red Hat would like to thank Man Yue Mo (Semmle) for reporting CVE-2017-7545.