RHSA-2017:0829HighCVSS 7.8
Red Hat Security Advisory: jboss-ec2-eap security, bug fix, and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2016-6346 — RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack CVE-2016-8657 — jboss: jbossas writable config files allow privilege escalation CVE-2017-6056 — tomcat: Infinite loop in the processing of https requests
🎯 Affected products4
- Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-ec2-eap-0:7.5.14-2.Final_redhat_2.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-ec2-eap-0:7.5.14-2.Final_redhat_2.ep6.el6.src as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
- jboss-ec2-eap-samples-0:7.5.14-2.Final_redhat_2.ep6.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2017:0829
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/?version=6.4
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1372120
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1400343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1422148
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_0829.json