RHSA-2018:0005HighCVSS 9.8

Red Hat Security Advisory: eap7-jboss-ec2-eap security update

Published
January 3, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2016-6346 — RESTEasy: Abuse of GZIPInterceptor in RESTEasy can lead to denial of service attack CVE-2017-7559 — undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) CVE-2017-7561 — resteasy: Vary header not added by CORS filter leading to cache poisoning CVE-2017-12165 — undertow: improper whitespace parsing leading to potential HTTP request smuggling CVE-2017-12167 — EAP-7: Wrong privileges on multiple property files CVE-2017-12189 — jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656) CVE-2017-12629 — Solr: Code execution via entity expansion

🎯 Affected products8

  • Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
  • Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
  • eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
  • eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el6.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
  • eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
  • eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server
  • eap7-jboss-ec2-eap-samples-0:7.0.9-2.GA_redhat_2.ep7.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server
  • eap7-jboss-ec2-eap-samples-0:7.0.9-2.GA_redhat_2.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server

✅ Remediation

Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Until fixes are available, all Solr users are advised to restart their Solr instances with the system parameter `-Ddisable.configEdit=true`. This will disallow any changes to be made to configurations via the Config API. This is a key factor in this vulnerability, since it allows GET requests to add the RunExecutableListener to the config. This is sufficient to protect from this type of attack, but means you cannot use the edit capabilities of the Config API until further fixes are in place.

🔗 References (14)