Red Hat released Important-rated updates for JBoss Data Virtualization to remediate multiple flaws in integrated components, including Apache HttpComponents, PicketLink, Xerces/OpenJDK, Mojarra JSF, Tomcat/JBossWeb, RESTEasy, and Netty. The updates address SSL hostname-verification bypasses, XML external entity processing, request smuggling, cross-site scripting, information disclosure, and denial-of-service vulnerabilities; affected releases include Data Virtualization 6.0.0, with a roll-up patch and the 6.1.0 release delivered through the Red Hat Customer Portal.
Among the remediated issues, CVE-2014-0075 affects Tomcat and JBoss Web HTTP chunked-transfer input handling. An unauthenticated remote attacker could submit an unlimited-length chunk-size value and consume server resources, causing a denial of service. Red Hat advised customers to back up affected installations, stop the JBoss Application Server, install the update, and restart services; JBoss Enterprise Application Platform 5 was not scheduled for a fix because of its reduced Phase 2 maintenance status.

See real exploitation activity before you spend the cycle.
34 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2015:1888 for JBoss SOA Platform 5.3.1, fixing seven vulnerabilities including remote-code-execution flaws in XStream, Xalan-Java, and JBoss Seam; PicketLink XXE; and SSL hostname-verification flaws in Apache HttpComponents, Apache CXF, and Not Yet Commons SSL. Users were advised to back up installations, stop JBoss Application Server, install the update, and restart the server.
Red Hat issued RHSA-2015:0765, an Important cumulative update for JBoss Data Virtualization 6.0.0, fixing CVE-2014-0075 and multiple SSL-bypass, XXE, denial-of-service, request-smuggling, XSS, and information-disclosure flaws.
RHSA-2015:0675, rated Important, released JBoss Data Virtualization 6.1.0 as a replacement for version 6.0.0 and fixed CVE-2014-0075 along with numerous other vulnerabilities.
Red Hat issued RHSA-2014:1834 for JBoss Enterprise Application Platform 5.2.0 on RHEL 4, 5, and 6, updating Apache CXF packages to remediate CVE-2012-6153 and CVE-2014-3577. The SSL hostname-verification flaws could allow a man-in-the-middle attacker using a specially crafted X.509 certificate to impersonate an SSL server; users were advised to back up installations, apply prior errata, and restart JBoss.
Red Hat issued RHSA-2014:1833 for JBoss Enterprise Web Platform 5.2.0 on RHEL 4, 5, and 6, updating apache-cxf packages to remediate CVE-2012-6153 and CVE-2014-3577. The hostname-validation flaws could allow a man-in-the-middle attacker using a crafted X.509 certificate to spoof an SSL server; Red Hat instructed users to restart JBoss after updating.
Red Hat issued Important advisory RHSA-2014:1321 for JBoss Enterprise Application Platform 5.2.0 on RHEL 4, 5, and 6, fixing CVE-2012-6153 and CVE-2014-3577. The Apache HttpComponents/HttpClient flaws could allow a man-in-the-middle attacker to spoof an SSL server with a crafted X.509 certificate; users were instructed to apply updates and restart JBoss.
Red Hat issued RHSA-2014:1320 for JBoss Enterprise Web Platform 5.2.0 on RHEL 4, 5, and 6, fixing CVE-2012-6153 and CVE-2014-3577 in Apache HttpComponents hostname validation. The flaws could allow an on-path attacker to spoof an SSL server using a specially crafted X.509 certificate; users were instructed to install the packages and restart JBoss.
Red Hat issued Important advisory RHSA-2014:1162 for JBoss Enterprise Application Platform 6.3.0 on RHEL 5, 6, and 7, fixing CVE-2012-6153 and CVE-2014-3577 in Apache HttpComponents/HttpClient. The flaws could allow an on-path attacker using a crafted X.509 certificate to spoof an SSL server; administrators were instructed to update the packages and restart JBoss.
Red Hat issued Important advisory RHSA-2014:1146 for Red Hat Enterprise Linux 7, updating httpcomponents-client to version 4.2.5-5.el7_0 to remediate CVE-2014-3577. The incomplete hostname-verification fix could allow a man-in-the-middle attacker using a crafted X.509 certificate to spoof an SSL server.
Red Hat issued RHSA-2014:1098 for Red Hat Developer Toolset 2.1 on RHEL 6, updating devtoolset-2-httpcomponents-client to address CVE-2012-6153, an SSL/TLS hostname-verification flaw that could enable server spoofing by a network-based man-in-the-middle attacker.
Red Hat issued Important advisory RHSA-2014:1082 for thermostat1-httpcomponents-client in Red Hat Software Collections 1, providing a backported CVE-2014-3577 fix in thermostat1-httpcomponents-client-4.2.5-3.4.el6.1. The advisory was updated on August 25 to clarify that CVE-2012-6153 did not itself affect these packages.
Red Hat published CVE-2014-3530, an Important PicketLink XML external entity vulnerability reported by Alexander Papadakis. Crafted XML could cause vulnerable applications to read files available to the application-server user and potentially enable SSRF or denial-of-service attacks.
Red Hat remediated the chunked-transfer denial-of-service flaw in the Red Hat Enterprise Linux 6 tomcat6 package through RHSA-2014:0865.
Red Hat issued fixes for JBoss Enterprise Application Platform 6.2 through RHSA-2014:0842 and for its RHEL 5 and RHEL 6 jbossweb packages through RHSA-2014:0843.
Red Hat fixed CVE-2014-0075 in the Red Hat Enterprise Linux 7 tomcat package through advisory RHSA-2014:0827.
Red Hat remediated CVE-2014-0059, a Low-severity vulnerability in which PicketBox and JBossSX wrote sensitive audit information to a world-readable audit.log file, allowing local unauthenticated users to read it. Fixes were issued for JBoss EAP 6.2 and subsequently for Data Grid 6.3, Data Virtualization 6.1, BRMS 6.0, and BPMS 6.0.
Arun Babu Neelicattu reported CVE-2014-0059 in JBossSX and PicketBox auditing functionality. The flaw caused sensitive, potentially session-related audit data to be written to a world-readable audit.log file, enabling local users to access protected information.
CVE-2013-7397, an Important improper certificate-validation flaw in async-http-client, was publicly disclosed. Under conditions including HTTPS connections using client certificates, the component could disable TLS certificate verification, enabling a network-based man-in-the-middle attacker to impersonate a trusted endpoint or tamper with communications.
Red Hat released RHSA-2013:0270 to update affected jakarta-commons-httpclient packages in Red Hat Enterprise Linux 5 and 6 for CVE-2012-5783. Apache Commons HttpClient 3.x failed to validate certificate Common Name and subjectAltName values, allowing a man-in-the-middle attacker with an arbitrary valid certificate to spoof an SSL/TLS server.
CVE-2013-7398, an Important improper certificate hostname-validation flaw in async-http-client, was public. The component did not verify a TLS server hostname against certificate CN or subjectAltName values, allowing a man-in-the-middle attacker with a certificate for another domain to spoof the intended server.
In November 2012, Red Hat Product Security determined that Apache HttpClient's fix for CVE-2012-5783 incorrectly validated certificate subject CN values, enabling man-in-the-middle certificate spoofing. The issue was assigned CVE-2012-6153, and an upstream correction was incorporated into HttpClient 4.2.3.
Red Hat documented that CVE-2014-3577 resulted from incomplete hostname-validation fixes for CVE-2012-5783 and CVE-2012-6153: parsing certificate-subject strings for "CN=" could let a man-in-the-middle attacker spoof a server using a crafted certificate. The disclosure identified affected HttpComponents and Commons HttpClient versions, numerous product-specific updates, and legacy products that would not receive fixes because of support status.
Red Hat rated CVE-2014-3577 Important and issued advisories for affected RHEL, JBoss, OpenShift, and related products. The flaw in Apache HttpComponents Client could allow a man-in-the-middle attacker to spoof an SSL server using a specially crafted X.509 certificate.
Red Hat identified JBoss SOA Platform 4 as affected by the Not Yet Commons SSL hostname-validation flaw CVE-2014-3604, but marked the product will not fix because it was in Phase 3 Extended Life Support. The flaw could allow a network-based attacker using a crafted certificate subject to spoof a trusted server.
Fedora 20's stable repository received async-http-client-1.7.22-2.fc20, addressing CVE-2013-7397, in which certificate verification could be disabled during HTTPS connections using client certificates. The flaw could enable a man-in-the-middle attacker to intercept or modify protected communications.
Red Hat stated that JBoss Enterprise Application Platform 5 was affected by CVE-2014-0075 but would not receive a fix because Phase 2 maintenance support provided only Critical and Important security updates.
Red Hat issued RHSA-2015:0851 to fix components affected by CVE-2012-6153 in Red Hat JBoss BPMS 6.0. The vulnerability is an incomplete SSL hostname-verification fix that could enable man-in-the-middle SSL server spoofing with a crafted X.509 certificate.
Fedora 21 received tomcat-7.0.59-1.fc21 in its stable repository, addressing the affected Tomcat behavior.
Red Hat issued RHSA-2015:0234 for JBoss BPMS 6.0 and RHSA-2015:0235 for JBoss BRMS 6.0, remediating CVE-2014-0075 in their jbossweb components.
Red Hat released RHSA-2014:1892, an Important cumulative Roll Up Patch 1 for JBoss BPM Suite 6.0.3. The update fixes CVE-2012-6153 and CVE-2014-3577, which could allow a man-in-the-middle attacker to spoof an SSL server using a crafted X.509 certificate.
Red Hat fixed CVE-2014-0075 for JBoss Data Grid 6.3 through advisory RHSA-2014:0895.
Red Hat addressed the PicketLink XXE flaw CVE-2014-3530 through updates for multiple JBoss products, including EAP, Enterprise Web Platform, Operations Network, Data Grid, BRMS, BPM Suite, Data Virtualization, Fuse Service Works, and Portal. The listed advisories include RHSA-2014:0883 through RHSA-2014:0910 and subsequent 2015 advisories.
Upstream fixes for the chunk-size handling flaw were committed to Apache Tomcat 6 and Tomcat 7 in SVN revisions 1579262 and 1578341, respectively.
David Jorm of Red Hat Product Security identified a flaw in HTTP chunked-transfer handling: unlimited chunk-size lengths could let an unauthenticated remote attacker exhaust server resources and cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
36 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.