Red Hat released JBoss Web Server 2.1.0 for Red Hat Enterprise Linux 5 and 6, replacing version 2.0.1 and addressing five Apache HTTP Server and Apache Tomcat vulnerabilities. The update fixes a mod_status heap-buffer-overflow issue that could enable remote code execution, denial-of-service flaws in mod_deflate and mod_cgid, and XML-processing weaknesses including XXE information disclosure.
The release also remediates CVE-2014-0119, in which a malicious application could, in limited circumstances, hijack XML parsers used by Tomcat/JBoss Web. This could bypass XXE restrictions and expose XML files handled by other applications on the same server instance. Red Hat advised affected users to apply prerequisite errata, back up applications and configurations, upgrade to JBoss Web Server 2.1.0, and restart the JBoss server process.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2015:0991 for tomcat6 on RHEL 6 and RHSA-2015:0983 for Tomcat on RHEL 7, fixing the CVE-2014-0227 malformed chunked-request vulnerability that could enable request smuggling or limited denial of service.
Red Hat issued RHSA-2014:1087 and RHSA-2014:1088, making JBoss Web Server 2.1.0 available for RHEL 6 and RHEL 5, respectively. The updates replaced version 2.0.1 and remediated CVE-2014-0119 along with Apache HTTP Server and Tomcat flaws including CVE-2014-0226, CVE-2014-0118, CVE-2014-0231, and CVE-2013-4590.
Red Hat issued RHSA-2014:0842 and RHSA-2014:0843 to fix the XML-parser hijacking flaw in JBoss Enterprise Application Platform 6.2 deployments on RHEL 5 and RHEL 6.
Red Hat addressed the Apache Commons FileUpload/Tomcat 7 denial-of-service flaw (CVE-2014-0050) through updates for Fedora, RHEL, EAP, JBoss BRMS and BPM Suite, A-MQ, Fuse, Fuse Service Works, Operations Network, Enterprise Web Server, and JBoss Portal. The flaw could cause affected Tomcat 7 instances to loop indefinitely when processing a crafted multipart Content-Type header.
Red Hat addressed CVE-2014-0119 in JBoss Portal 6.2.0 through RHSA-2015:1009.
Red Hat addressed CVE-2014-0119 in Red Hat JBoss Fuse Service Works 6.0.0 through RHSA-2015:0720.
Red Hat issued RHSA-2015:0765 to remediate CVE-2014-0119 in Red Hat JBoss Data Virtualization 6.0.
Red Hat issued RHSA-2015:0675 to remediate CVE-2014-0119 in Red Hat JBoss Data Virtualization 6.1.
Red Hat issued RHSA-2015:0234 and RHSA-2015:0235 to address CVE-2014-0119 in Red Hat JBoss BPM Suite 6.0 and Red Hat JBoss BRMS 6.0.
Red Hat issued RHSA-2014:1038 to fix CVE-2014-0119 in the Tomcat6 component for Red Hat Enterprise Linux 6.
Red Hat issued RHSA-2014:1034 to remediate CVE-2014-0119 in the Tomcat component for Red Hat Enterprise Linux 7.
Red Hat issued RHSA-2014:0895, addressing CVE-2014-0119 in JBoss Data Grid 6.3.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.