Red Hat released RHSA-2017:0247 to update JBoss Enterprise Application Platform 6 from 6.4.12 to 6.4.13, addressing HTTP request smuggling (CVE-2016-6816), log-download resource exhaustion (CVE-2016-8627), and sensitive-information disclosure through role-based access control (CVE-2016-7061). The log-download flaw could allow cross-origin GET requests to consume server resources and impair service availability, while the RBAC flaw let Monitor-role users in domain mode view sensitive socket-binding and internal network configuration at the server level.
For EAP 6.4 deployments on RHEL 6 using the EC2 package, RHSA-2017:0250 supplied jboss-ec2-eap-7.5.13-1.Final_redhat_2.ep6.el6 and included fixes for these issues plus a local privilege-escalation issue. Red Hat later clarified that CVE-2016-8656, an unsafe-file-handling flaw in JBoss initialization scripts affecting RPM installations, was incorrectly listed as resolved by RHSA-2017:0247 because that advisory covered ZIP-distributed EAP files; affected organizations should apply the applicable supported EAP and package updates after backing up installations and deployed applications.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat updated a knowledgebase notice describing Apache Tomcat returning HTTP 400 responses after updates intended to mitigate CVE-2016-6816. The issue was listed for JBoss Web Server 3.1, JBoss EAP 6.4.13 and later, and Tomcat deployments on RHEL 6 and 7.
Red Hat issued RHSA-2018:1609 to remediate the JBoss initialization-script local privilege-escalation vulnerability in JBoss EAP 5 packages for RHEL 5 and RHEL 6.
Red Hat updated RHSA-2017:0247 to state that CVE-2016-8656 had been incorrectly listed as resolved. The company clarified that the flaw affected RPM installations, not the ZIP-distributed files covered by that erratum.
Red Hat issued RHSA-2017:0935 for Apache Tomcat on RHEL 7, providing tomcat-7.0.69-11.el7_3. The update remediated HTTP response injection CVE-2016-6816 and CVE-2016-8745, an NIO connector flaw that could leak session IDs and response bodies between requests.
Red Hat released RHSA-2017:0527 to remediate CVE-2016-6816, an HTTP request-smuggling flaw in Red Hat Enterprise Linux 6 tomcat6. The vulnerability could allow unauthenticated remote attackers to inject data into HTTP responses when a proxy and Tomcat interpret invalid request-line characters differently.
Red Hat issued RHSA-2017:0245 for JBoss EAP 6.4 on RHEL 7, updating EAP from 6.4.12 to 6.4.13. The advisory remediated CVE-2016-8656, CVE-2016-6816, CVE-2016-8627, and CVE-2016-7061.
Red Hat issued RHSA-2017:0244 for JBoss EAP 6.4 on RHEL 6, updating EAP from 6.4.12 to 6.4.13. The advisory remediated CVE-2016-8656, CVE-2016-6816, CVE-2016-8627, and CVE-2016-7061.
Red Hat issued RHSA-2017:0173 for eap7-jboss-ec2-eap on RHEL 6 and RHEL 7, providing version 7.0.4-5.GA_redhat_2. The EC2 operating-scripts update remediated the server-log resource-starvation issue CVE-2016-8627 and Monitor-role sensitive-information disclosure CVE-2016-7061.
Red Hat issued RHSA-2017:0171 for JBoss EAP 7.0 on RHEL 7, replacing EAP 7.0.3 with 7.0.4. The Moderate-severity update remediated CVE-2016-8627, a cross-origin server-log request resource-starvation flaw, and CVE-2016-7061, an RBAC sensitive-information disclosure flaw.
Red Hat issued RHSA-2017:0170 for JBoss EAP 7.0 on RHEL 6, replacing EAP 7.0.3 with 7.0.4. The Moderate-severity update remediated CVE-2016-8627, a cross-origin server-log request resource-starvation flaw, and CVE-2016-7061, an RBAC information-disclosure flaw.
Red Hat issued RHSA-2017:0172 to fix the server-log resource-exhaustion flaw (CVE-2016-8627) and the RBAC sensitive-information disclosure flaw (CVE-2016-7061) in JBoss EAP 7.
A potential resource-starvation denial-of-service issue in EAP's server-log download feature was described. Repeated GET requests for log files could consume resources and impair normal server operation.
A flaw allowing EAP domain-mode users assigned the Monitor role to view sensitive server-level socket-binding configuration was reported. The exposed data could include internal addresses and port settings.
CVE-2016-8656 was published for unsafe file handling in the JBoss initialization script that could enable local privilege escalation in JBoss EAP 5, 6, and 7.
Red Hat identified CVE-2016-8657 as a privilege-escalation vulnerability affecting JBoss Enterprise Application Platform, alongside CVE-2016-8656. The issues were found during follow-on research into similar Tomcat initialization-script flaws.
Red Hat issued RHSA-2017:3456 for JBoss EAP and advisories RHSA-2017:3454, RHSA-2017:3455, and RHSA-2017:3458 for EAP 7.1 deployments, addressing CVE-2016-8627 and CVE-2016-7061 across supported RHEL releases.
Red Hat stated that CVE-2016-8656, an unsafe JBossAS init-script file-handling flaw allowing local privilege escalation, was corrected in JBoss EAP 6.4.13 and EAP 7.0.5. It issued advisories for affected EAP 6 and EAP 7 deployments on supported RHEL releases.
Red Hat released RHSA-2017:0247, updating JBoss EAP 6 from 6.4.12 to 6.4.13 and fixing CVE-2016-6816, CVE-2016-8627, and CVE-2016-7061. It also issued RHSA-2017:0246 for EAP 6.4 RHEL 5 components and RHSA-2017:0250 for the EC2 EAP package on RHEL 6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
28 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.