Red Hat released RHSA-2016:0062 for JBoss Web Server 2.1.0 to address CVE-2015-3183, CVE-2013-5704, and CVE-2012-0876. In particular, CVE-2013-5704 lets an unauthenticated remote client add HTTP Trailer headers to chunked requests after other modules have processed headers, potentially bypassing restrictions enforced with mod_headers. The update also addresses HTTP request-smuggling risk and an Expat XML parsing flaw that could enable CPU-exhaustion denial of service; affected users were advised to apply the update and restart the service.
HP also issued HPSBUX03512 (SSRT102254) for HP-UX Web Server Suite running Apache, citing remote denial of service, access-control bypass, unauthorized modification, information disclosure, and SSL/TLS weaknesses including Logjam and Bar Mitzvah. HP identified Web Server Suite 2.2.15.21 Apache on HP-UX 11i v2 as affected and directed administrators to install updated packages, including Apache B.2.2.15.18 or later and, where applicable, Tomcat C.6.0.35.01 or later.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat corrected the RHSA-2016:0062 erratum to clarify that CVE-2012-1148 was not fixed by the advisory.
Red Hat issued Moderate-severity RHSA-2016:0062 for JBoss Web Server 2.1.0, fixing CVE-2015-3183, CVE-2013-5704, and CVE-2012-0876. The company advised affected users to apply the update and restart the JBoss Web Server process.
Hewlett-Packard issued HPSBUX03512 (SSRT102254 rev.1) for HP-UX Web Server Suite, addressing multiple Apache-related vulnerabilities including CVE-2013-5704 and CVE-2015-3183. HP provided software updates and instructed administrators to install updated Apache and, where applicable, Tomcat revisions.
Red Hat released RHSA-2015:1249 for Red Hat Enterprise Linux 6, providing a fix for CVE-2013-5704.
Red Hat released RHSA-2015:0325 for Red Hat Enterprise Linux 7, fixing the Apache HTTP Server Trailer-header handling flaw CVE-2013-5704.
Apache addressed the HTTP Trailer-header handling flaw CVE-2013-5704 in Apache HTTP Server 2.2.28 and 2.2.29. The fix introduced the MergeTrailers configuration directive, which can restore previous trailer-handling behavior.
Red Hat issued RHSA-2016:2957 for Red Hat JBoss Web Server, providing a fix for the Expat hash-collision denial-of-service vulnerability CVE-2012-0876.
Red Hat released RHSA-2016:0061 for JBoss Enterprise Web Server 2 on RHEL 5, 6, and 7, updating affected httpd and mod_cluster-native components to address CVE-2013-5704.
Red Hat released RHSA-2015:2661 for JBoss Web Server 3.0, fixing CVE-2013-5704.
Red Hat addressed the Expat hash-collision denial-of-service vulnerability CVE-2012-0876 for Red Hat Enterprise Linux 5 and 6 through RHSA-2012:0731.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.