Red Hat released an important-security update for JBoss Enterprise Application Platform (EAP) 5.1.2, addressing multiple flaws in its JBoss Web component. The fixes mitigate remote denial-of-service attacks triggered by malformed UTF-8 surrogate pairs, hash-collision parameter names, and excessive request parameters or values; the update also introduces default limits of 512 parameters and 128 headers per request to reduce resource exhaustion risk.
The update corrects HTTP Digest authentication weaknesses, including CVE-2011-5062, in which improper validation of qop values could let remote attackers select qop=auth and bypass intended integrity protections. It also fixes a sendfile issue through which a malicious deployed web application could evade Security Manager restrictions, read unauthorized files, or potentially terminate the JVM. Red Hat advised EAP 5.1.2 users to back up customized configurations and install the update.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2013:0623 for Red Hat Enterprise Linux 6, providing updated Tomcat 6 packages that fix FORM-authentication authorization bypass, NIO/HTTPS sendfile denial of service, and DIGEST-authentication weaknesses that could enable replay attacks. Administrators were instructed to install the updated packages and restart Tomcat.
CVE-2011-5062 was published, documenting that affected Apache Tomcat HTTP Digest Access Authentication implementations did not validate qop values, allowing a remote attacker using qop=auth to bypass intended integrity protection.
Red Hat released an important-security-impact update for JBoss Enterprise Application Platform 5.1.2, fixing multiple JBoss Web vulnerabilities including denial-of-service, HTTP DIGEST authentication, and sendfile issues. The update introduced default limits of 512 request parameters and 128 headers, and Red Hat advised affected users to back up customized configurations and install it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcecve.mitre.org
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcelists.opensuse.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.