Red Hat issued updates for JBoss Enterprise Application Platform (EAP), BPM Suite, Process Automation Manager, Fuse, and related products to remediate flaws that could enable code execution, denial of service, file disclosure, and HTTP request smuggling. The most severe issue, CVE-2016-9606, allowed certain RESTEasy endpoints to deserialize attacker-controlled YAML via YamlProvider, potentially executing code with the affected application’s privileges. Red Hat removed the provider from RESTEasy’s default provider list; affected organizations should also ensure exposed REST endpoints enforce authentication and authorization where appropriate.
The updates additionally addressed CVE-2017-2666, an Undertow request-smuggling flaw caused by permissive parsing of invalid HTTP request characters; CVE-2017-2670, which could exhaust Undertow I/O threads through improperly closed WebSocket connections; and CVE-2017-2595, an authenticated WildFly log-viewer path traversal allowing arbitrary file reads. JBoss BPM Suite updates also fixed RESTEasy GZIPInterceptor denial of service (CVE-2016-6346) and Logback remote-logging deserialization (CVE-2017-5929), which could permit code execution when SocketServer or ServerSocketReceiver accepted untrusted serialized data. Red Hat advised customers to back up installations and deployed applications before applying the relevant replacement releases.

See real exploitation activity before you spend the cycle.
23 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2020:3133 for Red Hat AMQ's springframework component, remediating CVE-2018-15756. The flaw allowed resource exhaustion through Range headers containing numerous, overlapping, or excessively wide ranges.
Red Hat updated RHSA-2020:0983 to add component descriptions for multiple fixed CVEs and descriptions of Go vulnerabilities omitted from the original advisory.
Red Hat issued RHSA-2020:0983, replacing Red Hat Fuse 7.5 with 7.6.0 and remediating numerous component vulnerabilities, including HTTP/2 denial-of-service issues, Jackson deserialization flaws, and CVE-2017-5929 in Logback.
Red Hat released RHSA-2019:3200 for Red Hat AMQ Streams 1 to remediate CVE-2019-14439, a jackson-databind polymorphic deserialization vulnerability. Under unsafe polymorphic typing configurations, attackers could use ehcache or Logback JNDI gadget chains to achieve arbitrary code execution.
Red Hat issued RHSA-2017:2247 for the Tomcat component in Red Hat Enterprise Linux 7, remediating CVE-2016-6796. The flaw allowed a malicious web application to manipulate JSP Servlet configuration parameters and bypass a configured Java SecurityManager.
RHSA-2017:1675 updated JBoss BPM Suite from 6.4.3 to 6.4.4 and remediated CVE-2016-6346, CVE-2016-9606, and CVE-2017-5929.
Red Hat issued RHSA-2017:1551 to remediate CVE-2016-5018 in JBoss Enterprise Application Platform 6.4. The Apache Tomcat flaw allowed a malicious web application to use the accessible IntrospectHelper utility method to bypass a configured SecurityManager.
Red Hat issued RHSA-2017:1550, replacing JBoss EAP 6.4.15 with 6.4.16 for RHEL 5. It fixed CVE-2017-2595 and two Tomcat SecurityManager-bypass flaws, CVE-2016-5018 and CVE-2016-6796.
RHSA-2017:1409 updated JBoss EAP from 7.0.5 to 7.0.6, fixing CVE-2016-9606, CVE-2017-2595, CVE-2017-2666, and CVE-2017-2670. The update addressed RESTEasy YAML code execution, authenticated file reads, Undertow request smuggling, and WebSocket denial of service.
Red Hat issued RHSA-2017:1255 and RHSA-2017:1256, updating JBoss EAP 6.4.14 to 6.4.15 and fixing CVE-2016-9606. The RESTEasy YamlProvider flaw could allow untrusted YAML unmarshalling and code execution with application privileges.
Bharti Kundal reported CVE-2017-2670, in which a non-clean WebSocket TCP closure could cause an infinite loop on every Undertow I/O thread and exhaust resources.
Adam Mariš reported CVE-2017-2666 in Undertow HTTP request-line parsing. Acceptance of invalid characters enabled request smuggling when paired with a proxy that interpreted requests differently.
Andrej Nemec reported CVE-2017-5929, a Logback SocketServer and ServerSocketReceiver deserialization vulnerability. Authenticated adjacent-network attackers could submit malicious serialized objects and potentially execute code through gadget chains.
Red Hat issued RHSA-2017:0517 for JBoss EAP 6.4.14, remediating CVE-2016-6346, in which unnecessary RESTEasy GZIPInterceptor enablement could be abused for denial of service.
Adam Mariš reported CVE-2017-2595 in WildFly Server 10.x.x's log-file viewer. The flaw allowed an authenticated attacker to use path traversal to read arbitrary files.
Apache published additional patches for CVE-2016-5018 across the Tomcat 6.0.x, 7.0.x, 8.0.x, and 8.5.x maintenance branches. The flaw let a malicious web application bypass a configured Java SecurityManager through an accessible Tomcat utility method.
Red Hat addressed CVE-2016-6346 in Red Hat Satellite 6.5 for RHEL 7 through RHSA-2019:1222; the remediation included a non-vulnerable RESTEasy version via candlepin 2.5.8.
Red Hat issued RHSA-2018:2927 for multiple Satellite 6.4 RHEL 7 components, including candlepin and foreman, to address CVE-2017-5929.
RHSA-2018:2909 updated Red Hat Process Automation Manager from 7.0.2 to 7.1.0 and remediated CVE-2016-9606, the RESTEasy YAML unmarshalling remote-code-execution risk.
Red Hat issued RHSA-2018:2143 to remediate CVE-2016-6346 in JBoss BRMS 7.0.
Red Hat issued RHSA-2018:0003 for JBoss EAP 7, remediating CVE-2016-6346. EAP 7.0.7 had not contained the fix, while the later update addressed the GZIPInterceptor denial-of-service issue.
Red Hat issued RHSA-2017:1832 to remediate CVE-2017-5929 in JBoss A-MQ 6.3 and JBoss Fuse 6.3 components.
Red Hat remediated CVE-2016-6796, the Tomcat JSP Servlet configuration SecurityManager-bypass flaw, in JBoss Web Server 3 and multiple JBoss EAP 6.4 product variants through RHSA-2017:0455 through RHSA-2017:0457 and RHSA-2017:1548, RHSA-2017:1549, RHSA-2017:1551, and RHSA-2017:1552.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
25 references tracked. Mallory keeps watching after this page renders.
issues.jboss.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.