Red Hat released JBoss Enterprise Application Platform (EAP) 6.4.14 to replace 6.4.13 and remediate three security flaws across EAP 6 packages for supported RHEL 5, 6, and 7 deployments, including jboss-ec2-eap. CVE-2016-8657 allowed local members of the jboss group to modify the group-writable /etc/sysconfig/jbossas file; on RHEL 6 and earlier systems using legacy /etc/init.d service scripts, that file was sourced with root privileges during JBoss service operations, enabling local privilege escalation.
The release also fixes CVE-2017-6056, an Apache Tomcat HTTPS request-processing flaw that could trigger an infinite loop and denial of service, and CVE-2016-6346, where RESTEasy's GZIPInterceptor could be unnecessarily enabled and permit denial of service. Red Hat advised customers to back up EAP installations and deployed applications before updating. The vendor clarified that the initial ZIP-distribution advisory did not resolve CVE-2016-8657, because the affected writable configuration file was present in RPM-based installations.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2016-8656 was published, describing unsafe file handling in the JBoss initialization script that could allow a low-privileged local attacker to escalate privileges. Affected jbossas releases listed include 5.2.0-23, 6.4.13, and 7.0.5.
Red Hat issued Important advisory RHSA-2017:3458 updating eap7-jboss-ec2-eap for JBoss EAP 7.1 on RHEL 6 and 7 EC2 deployments. The update addressed 17 vulnerabilities, including code-execution flaws in Jackson Databind and JMSObjectMessage handling and the CVE-2016-8656 JBoss init-script local privilege-escalation flaw.
Red Hat clarified that RHSA-2017:0517 did not resolve CVE-2016-8657 because the flaw affected RPM installations rather than the ZIP-distributed software supplied by that erratum.
Red Hat released RHSA-2017:0826, RHSA-2017:0827, RHSA-2017:0828, and RHSA-2017:0829, updating EAP 6.4 deployments and the jboss-ec2-eap package. These updates addressed CVE-2016-8657, in which group-writable /etc/sysconfig/jbossas files could enable local root privilege escalation through legacy init scripts, as well as CVE-2017-6056 and CVE-2016-6346.
Red Hat issued Important advisory RHSA-2017:0517, replacing JBoss EAP 6.4.13 with 6.4.14 for ZIP-distributed EAP 6. The update fixed the Apache Tomcat HTTPS infinite-loop denial of service flaw CVE-2017-6056 and the RESTEasy GZIPInterceptor denial of service flaw CVE-2016-6346.
Red Hat remediated the Tomcat infinite-loop denial-of-service flaw CVE-2017-6056 in JBoss Enterprise Web Server 3.0.3 through RHSA-2016:1087 for RHEL 6, RHSA-2016:1088 for RHEL 7, and RHSA-2016:1089 for the ZIP distribution.
Red Hat closed Bugzilla issue 1400343 and directed users to the CVE-2016-8657 security page for product-specific updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.