RHSA-2014:1821: Red Hat JBoss Enterprise Application Platform 6.3.2 update
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:M/Au:N/C:N/I:N/A:C) | July 23, 2013 | November 27, 2014 | July 04, 2017 |
Description
Updated packages that provide Red Hat JBoss Enterprise Application Platform 6.3.2 and fix one security issue, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.
Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. A resource consumption issue was found in the way Xerces-J handled XML declarations. A remote attacker could use an XML document with a specially crafted declaration using a long pseudo-attribute name that, when parsed by an application using Xerces-J, would cause that application to use an excessive amount of CPU. (CVE-2013-4002) This release of JBoss Enterprise Application Platform also includes bug fixes and enhancements. A list of these changes is available from the JBoss Enterprise Application Platform 6.3.2 Downloads page on the Customer Portal. All users of Red Hat JBoss Enterprise Application Platform 6.3 on Red Hat Enterprise Linux 5 are advised to upgrade to these updated packages. The JBoss server process must be restarted for the update to take effect.
Scan For This Vulnerability
Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities
References
- APPLE-APPLE-SA-2013-10-15-1
- BID-61310
- CVE-2013-4002
- DISA_SEVERITY-Category I
- DISA_VMSKEY-V0040779
- IAVM-2013-A-0191
- REDHAT-RHSA-2013:1059
- REDHAT-RHSA-2013:1060
- REDHAT-RHSA-2013:1081
- REDHAT-RHSA-2013:1440
- REDHAT-RHSA-2013:1447
- REDHAT-RHSA-2013:1451
- REDHAT-RHSA-2013:1505
- REDHAT-RHSA-2014:1818
- REDHAT-RHSA-2014:1821
- REDHAT-RHSA-2014:1822
- REDHAT-RHSA-2014:1823
- REDHAT-RHSA-2015:0675
- REDHAT-RHSA-2015:0720
- REDHAT-RHSA-2015:0765
- REDHAT-RHSA-2015:0773
- XF-85260
Solution
redhat-upgrade-apache-cxfRelated Vulnerabilities
- ELSA-2014-1319 Moderate: Oracle Linux xerces-j2 security update
- RHSA-2013:1440: java-1.7.0-oracle security update
- ELSA-2013-1447 Important: Oracle Linux java-1.7.0-openjdk security update
- Java CPU October 2013 Java SE, JRockit, Java SE Embedded JAXP vulnerability (CVE-2013-4002)
- USN-2033-1: OpenJDK 6 vulnerabilities
- SUSE Linux Security Vulnerability: CVE-2013-4002
- Amazon Linux AMI: Security patch for java-1.6.0-openjdk (ALAS-2013-246) (multiple CVEs)
- RHSA-2013:1451: java-1.7.0-openjdk security update
- Amazon Linux AMI: Security patch for java-1.7.0-openjdk (ALAS-2013-235) (multiple CVEs)
- RHSA-2013:1447: java-1.7.0-openjdk security update
- RHSA-2014:1822: Red Hat JBoss Enterprise Application Platform 6.3.2 update
- HP-UX: CVE-2013-4002: Running Java7, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
- Gentoo Linux: CVE-2013-4002: IcedTea JDK: Multiple vulnerabilities
- ELSA-2013-1505 Important: Oracle Linux java-1.6.0-openjdk security update
- RHSA-2014:0414: java-1.6.0-sun security update
- USN-2089-1: OpenJDK 7 vulnerabilities
- RHSA-2013:1059: java-1.6.0-ibm security update
- Apple Java security update for CVE-2013-4002
- F5 Networks: K16872 (CVE-2013-4002): Java Runtime Environment vulnerability CVE-2013-4002
- Cent OS: CVE-2013-4002: CESA-2014:1319 (xerces-j2)
- RHSA-2014:1818: Red Hat JBoss Enterprise Application Platform 6.3.2 update
- RHSA-2013:1081: java-1.5.0-ibm security update
- RHSA-2014:1319: xerces-j2 security update
- RHSA-2013:1060: java-1.7.0-ibm security update
- ELSA-2013-1451 Critical: Oracle Linux java-1.7.0-openjdk security update
- RHSA-2013:1505: java-1.6.0-openjdk security update
- Amazon Linux AMI: Security patch for xerces-j2 (ALAS-2014-436) (CVE-2013-4002)