Red Hat released JBoss Enterprise Application Platform (EAP) 7.0.2 updates for RHEL 6, RHEL 7, and the eap7-jboss-ec2-eap package to remediate three security flaws: CVE-2016-5406, a domain-management RBAC propagation failure that can grant full administrative privileges on EAP 6.2–6.4 slave hosts; CVE-2016-4993, Undertow HTTP header injection and response splitting through unsanitized header input; and CVE-2015-0254, an XXE flaw in JSTL that can expose host resources and may enable arbitrary code execution.
The fixes were delivered in RHSA-2016:1838 for RHEL 6, RHSA-2016:1839 for RHEL 7, and RHSA-2016:1840 for EAP EC2 deployments. Affected organizations should back up EAP installations and deployed applications, apply the appropriate EAP 7.0.2 packages, and restart JBoss server processes to activate the remediations.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2016:1841 to fix CVE-2016-4993 and CVE-2016-5406 in JBoss EAP 7 products.
Red Hat released RHSA-2016:1840 for the eap7-jboss-ec2-eap package on RHEL 6 and RHEL 7, making it compatible with EAP 7.0.2. The Important update addressed CVE-2016-4993 and CVE-2016-5406, as well as CVE-2015-0254.
Red Hat published RHSA-2016:1839, an Important advisory delivering JBoss EAP 7.0.2 packages for RHEL 7. It fixed the Undertow header-injection issue CVE-2016-4993 and the EAP domain-management RBAC privilege-escalation issue CVE-2016-5406.
Red Hat issued RHSA-2016:1838, an Important advisory providing JBoss EAP 7.0.2 for RHEL 6. The update remediated CVE-2016-4993 HTTP header injection/response splitting and CVE-2016-5406 privilege escalation, alongside CVE-2015-0254.
Red Hat issued RHSA-2015:1695 for Red Hat Enterprise Linux 6 and 7 packages containing jakarta-taglibs-standard, fixing CVE-2015-0254. The Important JSTL XML external-entity vulnerability could allow access to host resources and potentially arbitrary code execution through XSL extensions.
Red Hat issued RHSA-2017:3456 as a subsequent JBoss EAP 7 erratum fixing CVE-2016-4993 and CVE-2016-5406.
Red Hat issued RHSA-2016:0121, RHSA-2016:0122, RHSA-2016:0123, and RHSA-2016:0124 to remediate CVE-2015-0254 in JBoss EAP 6.4.z on RHEL 5, RHEL 6, and RHEL 7. Red Hat advised users to upgrade to at least EAP 6.4.9 and set org.apache.taglibs.standard.xml.accessExternalEntity=false to prevent JSTL XXE attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.