Red Hat released JBoss Web Server 3.1.0 to replace version 3.0.3, remediating 11 vulnerabilities in Apache Tomcat and Commons FileUpload. The most severe issue, CVE-2016-8735, could enable remote code execution through JmxRemoteLifecycleListener in Tomcat instances built from EWS 2.x or JWS 3.x source distributions; Red Hat noted that standard RHEL Tomcat binary packages were not affected. The update also fixes CVE-2016-1240, an unsafe Tomcat init-script file-handling flaw that could allow local privilege escalation via a symlink attack on catalina.out.
Other fixes address writable Tomcat initialization configuration that could enable privilege escalation (CVE-2016-6325), SecurityManager bypasses and system-property disclosure (CVE-2016-6794), unauthorized access to global JNDI resources (CVE-2016-6797), username enumeration through timing differences (CVE-2016-0762), denial-of-service conditions, request or response manipulation, and information disclosure. Organizations running affected JBoss Web Server deployments should back up installations, applications, and configuration before upgrading; on RHEL 7, the httpd service restarts automatically after installation.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2017:2247 for the RHEL 7 Tomcat component, fixing CVE-2016-0762 username enumeration, CVE-2016-6794 system-property disclosure, and CVE-2016-6797 unauthorized global JNDI resource access.
Red Hat issued Moderate-severity RHSA-2017:1551, updating JBoss Enterprise Application Platform from 6.4.15 to 6.4.16. It addressed CVE-2017-2595 arbitrary-file reads through log-viewer path traversal and the CVE-2016-5018 and CVE-2016-6796 SecurityManager bypasses.
Red Hat issued RHSA-2017:0455, RHSA-2017:0456, and RHSA-2017:0457 to update affected JBoss Web Server 3 deployments to version 3.1.0. The updates remediated 11 Tomcat and Commons FileUpload vulnerabilities, including local privilege escalation, SecurityManager bypasses, JNDI access, request smuggling, information disclosure, and source-built JmxRemoteLifecycleListener RCE.
CVE-2016-6794 was publicly disclosed as a Tomcat configuration-file system-property replacement flaw. A malicious web application could bypass SecurityManager restrictions and read otherwise inaccessible system properties.
Red Hat released RHSA-2016:2045 for RHEL 6 tomcat6 and RHSA-2016:2046 for RHEL 7 tomcat, addressing CVE-2016-6325. The flaw allowed tomcat-group members or malicious deployed applications to exploit writable configuration files and escalate privileges.
Dawid Golunski released an advisory for CVE-2016-1240 affecting Debian-packaged Tomcat 6, 7, and 8. The vulnerable init script could be abused by a Tomcat-account attacker through symlinked log files to obtain root privileges.
CVE-2013-4286 was published for improper handling of inconsistent Content-Length and Transfer-Encoding headers in Tomcat HTTP and AJP connectors, enabling HTTP request-smuggling attacks.
CVE-2012-4431 was published for an Apache Tomcat CsrfPreventionFilter flaw affecting Tomcat 6 before 6.0.36 and Tomcat 7 before 7.0.32. Remote attackers could bypass CSRF protections by submitting a request without a session identifier.
CVE-2012-3546 was published for a RealmBase flaw in Tomcat 6 and 7 that could allow remote security-constraint bypasses when FORM authentication was enabled.
CVE-2010-1157 was published for an Apache Tomcat BASIC or DIGEST authentication issue that could expose a server hostname or IP address in the WWW-Authenticate realm field.
CVE-2008-0002 was published for an Apache Tomcat 6.0.0–6.0.15 flaw where an exception during parameter processing could associate parameters with the wrong request context and expose sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
22 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourceredhat.com
Open sourceredhat.com
Open sourcelegalhackers.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.