RHSA-2017:1411MediumCVSS 8.1
Red Hat Security Advisory: JBoss Enterprise Application Platform 7.0.6 on Red Hat Enterprise Linux 7
🔗 CVE IDs covered (4)
📋 Description
CVE-2016-9606 — Resteasy: Yaml unmarshalling vulnerable to RCE CVE-2017-2595 — wildfly: Arbitrary file read via path traversal CVE-2017-2666 — undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests CVE-2017-2670 — undertow: IO thread DoS via unclean Websocket closing
🎯 Affected products133
- Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-cli-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-commons-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-core-client-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-dto-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-hornetq-protocol-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-hqclient-protocol-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-jms-client-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-jms-server-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-journal-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-native-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-ra-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-selector-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-server-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-activemq-artemis-service-extensions-0:1.1.0-17.SP20_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-apache-cxf-0:3.1.10-2.redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-apache-cxf-0:3.1.10-2.redhat_1.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-apache-cxf-rt-0:3.1.10-2.redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-apache-cxf-services-0:3.1.10-2.redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-apache-cxf-tools-0:3.1.10-2.redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-commons-logging-jboss-logmanager-0:1.0.0-1.Final_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-commons-logging-jboss-logmanager-0:1.0.0-1.Final_redhat_1.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-glassfish-javamail-0:1.5.5-2.redhat_2.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-glassfish-javamail-0:1.5.5-2.redhat_2.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-hibernate-0:5.0.13-1.Final_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-hibernate-0:5.0.13-1.Final_redhat_1.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-hibernate-core-0:5.0.13-1.Final_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- eap7-hibernate-entitymanager-0:5.0.13-1.Final_redhat_1.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
- +103 more not shown
✅ Remediation
Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Add authentication and authorization to any Resteasy endpoint which doesn't define a mime type, or defines a multipart mime type.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2017:1411
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/version-7.0/
- externalhttps://access.redhat.com/documentation/en/red-hat-jboss-enterprise-application-platform/version-7.0/installation-guide/
- externalhttps://access.redhat.com/documentation/en/jboss-enterprise-application-platform/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1400644
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1413028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1436163
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1438885
- externalhttps://issues.redhat.com/browse/JBEAP-8076
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2017/rhsa-2017_1411.json