Red Hat fixed CVE-2016-9589, a CVSS 7.5 denial-of-service vulnerability in the HTTP Header Cache of JBoss Enterprise Application Platform (EAP) 7 and related Undertow/WildFly components. An unauthenticated remote attacker could send garbage headers over persistent TCP connections, causing cached header values to consume heap memory until service availability is disrupted. Memory use could grow with each active connection, up to the configured header-count and header-size limits; cited defaults allowed 200 headers of up to 1 MB each per connection.
The flaw, tracked upstream as WFLY-7725 and classified as CWE-400 uncontrolled resource consumption, was remediated in JBoss EAP 7.0.5 through Red Hat advisories RHSA-2017:0830, RHSA-2017:0831, RHSA-2017:0834, and RHSA-2017:3456, including EAP deployments on RHEL 6 and RHEL 7 and affected Red Hat Single Sign-On releases. Organizations should apply the applicable EAP updates after backing up existing installations and deployed applications; the same update stream also addressed the local privilege-escalation issue CVE-2016-8656 in certain EAP packages.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2017:0832, updating JBoss EAP 7.0 on RHEL 7 from 7.0.4 to 7.0.5. The advisory fixed CVE-2016-9589 and CVE-2016-8656, a local privilege-escalation flaw involving unsafe ownership handling of server.log by the JBoss init script.
Red Hat issued RHSA-2017:0834 for the eap7-jboss-ec2-eap package on RHEL 6 and 7, updating it to version 7.0.5 and addressing the Header Cache denial-of-service vulnerability.
Red Hat issued RHSA-2017:0830 and RHSA-2017:0831 to fix CVE-2016-9589 in JBoss EAP 7, including an update of JBoss EAP 7.0 on RHEL 6 from version 7.0.4 to 7.0.5.
Red Hat released RHSA-2017:3456 to fix CVE-2016-9589 in JBoss EAP 7. Related advisories RHSA-2017:3454, RHSA-2017:3455, and RHSA-2017:3458 also addressed the issue for JBoss EAP products on RHEL 6 and RHEL 7.
Gabriel Lavoie of Halogen Software reported the inefficient Header Cache issue in JBoss EAP 7, which could allow an unauthenticated remote attacker to exhaust heap memory and cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.