Red Hat disclosed CVE-2014-0248, an important-severity code-injection flaw in JBoss Seam's org.jboss.seam.web.AuthenticationFilter. Improper use of Seam logging allows an unauthenticated remote attacker to submit specially crafted authentication headers and execute arbitrary code with the privileges of the affected application process. Red Hat classified the vulnerability as CWE-94 and assigned it a CVSS v2 base score of 6.8; Marek Schmidt of Red Hat discovered the issue.
Affected products included JBoss Enterprise Application Platform 5.2.0, JBoss Enterprise Web Platform 5.2.0, JBoss Web Framework Kit, JBoss Web Platform, and JBoss SOA Platform 5.3. Red Hat released updates through advisories including RHSA-2014:0792, RHSA-2014:0793, RHSA-2014:0794, and RHSA-2015:1888; administrators should install the applicable updated jboss-seam2 packages or platform updates and restart JBoss server processes. Red Hat BPM Suite 6 was not affected.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat closed Bugzilla 1101619, the tracking record for the JBoss Seam AuthenticationFilter remote-code-execution vulnerability.
Red Hat released RHSA-2015:1888, an Important update for JBoss SOA Platform 5.3.1. The advisory fixed CVE-2014-0248 along with six other vulnerabilities, including XStream, Xalan-Java, PicketLink, and hostname-verification flaws.
CVE-2014-0248 was published for a Seam logging flaw in org.jboss.seam.web.AuthenticationFilter. Crafted authentication headers could allow remote attackers to execute arbitrary code in affected JBoss Seam deployments.
Red Hat addressed CVE-2014-0248 in JBoss Web Platform 5.2 through security advisory RHSA-2014:0791.
Red Hat issued RHSA-2014:0792, an Important security update for JBoss Enterprise Web Platform 5.2.0 on RHEL 4, 5, and 6. The update fixed CVE-2014-0248 through updated jboss-seam2 packages.
Red Hat issued RHSA-2014:0794, an Important update for JBoss Enterprise Application Platform 5.2.0 that fixed CVE-2014-0248. The flaw allowed unauthenticated remote attackers to execute code as the affected application's running user via crafted authentication headers.
Red Hat released RHSA-2014:0793, an Important update for JBoss Enterprise Application Platform 5 on RHEL 4, 5, and 6, fixing CVE-2014-0248. The update supplied remediated jboss-seam2 packages and required a JBoss server restart.
Red Hat issued RHSA-2014:0785 to remediate CVE-2014-0248 in Red Hat JBoss Web Framework Kit 2.5.
Arun Babu Neelicattu reported CVE-2014-0248 as Red Hat Bugzilla 1101619. The unsafe logging behavior in JBoss Seam's AuthenticationFilter could let remote attackers use crafted authentication headers to execute arbitrary code.
CVE-2008-3271 was published for a thread-safety flaw in Apache Tomcat RemoteFilterValve, RemoteAddrValve, and RemoteHostValve. Concurrent requests could overwrite an instance variable, allowing remote attackers to bypass IP-address restrictions and obtain sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.