Red Hat released Moderate-impact updates for Apache Tomcat, JBoss Web Server, JBoss EAP 6.2.4, and JBoss Data Grid to remediate CVE-2014-0075, CVE-2014-0099, and CVE-2014-0096. The flaws could permit remote denial of service through unbounded chunked-transfer input, HTTP request smuggling via integer overflow while parsing Content-Length headers—particularly where a vulnerable server sits behind a reverse proxy—and XML external entity (XXE) processing in Tomcat DefaultServlet handling of user-supplied XSLTs. JBoss EAP and Data Grid updates additionally addressed XML parser abuse that could bypass XXE restrictions and expose XML files belonging to other applications on the same instance.
Affected RHEL 6 and 7 Tomcat deployments, JBoss Web Server 2.0.1 installations, and EAP 6.2.4 environments should install the applicable vendor packages or upgrades and restart Tomcat or the JBoss server process. Red Hat supplied patched builds including tomcat-7.0.42-6.el7_0 for RHEL 7 and tomcat6-6.0.24-72.el6_5 for RHEL 6; JBoss Data Grid 6.2.1 users were directed to upgrade to 6.3.0. Administrators should back up JBoss installations, applications, and configurations before applying updates, and prioritize externally reachable services deployed behind reverse proxies.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
IBM disclosed that WebSphere Message Broker 8.0 and IBM Integration Bus 9.0 were affected by Apache Tomcat vulnerabilities CVE-2014-0075 and CVE-2014-0099. IBM assigned APAR IT02891 and targeted fixes in WebSphere Message Broker 8.0.0.5 and IBM Integration Bus 9.0.0.3; no workaround was known.
IBM published a bulletin stating that Rational Build Forge 7.1.2 through 7.1.2.3 Web Console components were affected by Apache Tomcat CVE-2014-0075 and CVE-2014-0099. IBM identified Build Forge 7.1.2.3 iFix2 as the planned fix, advised customers to contact support or upgrade the bundled Tomcat server, and listed Build Forge 8.0.0.2 Fix Pack 2 as an alternative mitigation path.
Red Hat issued RHSA-2014:0865, a Moderate-severity Tomcat 6 security and bug-fix update for RHEL 6. It remediated the chunked-transfer denial-of-service flaw, the Content-Length request-smuggling flaw CVE-2014-0099, and the DefaultServlet XXE flaw CVE-2014-0096.
Red Hat issued RHSA-2014:0834 and RHSA-2014:0835 for JBoss Web Server 2.0.1 on RHEL 5 and 6. Updated Tomcat 6 and Tomcat 7 packages remediated CVE-2014-0075, CVE-2014-0099, and CVE-2014-0096, requiring a JBoss Web Server restart after installation.
Red Hat issued RHSA-2014:0827, a Moderate-impact update for Apache Tomcat on RHEL 7. The patched packages fixed CVE-2014-0075, CVE-2014-0099, and CVE-2014-0096; users were instructed to upgrade and restart Tomcat.
CVE-2014-0099 was published for an integer overflow in Apache Tomcat's Ascii.java that permits HTTP request smuggling through a crafted Content-Length header when Tomcat is deployed behind a reverse proxy. It affects Tomcat versions before 6.0.40, 7.0.53, and 8.0.4.
IBM X-Force reported CVE-2014-0099, an unauthenticated Apache Tomcat information-disclosure vulnerability caused by integer-overflow handling failures when parsing Content-Length headers. Apache fixed the issue in Tomcat 8.0.5, 7.0.53, and 6.0.41; IBM rated it CVSS v2 5.0.
IBM X-Force reported CVE-2014-0075, an unauthenticated Apache Tomcat denial-of-service vulnerability caused by an integer overflow in parseChunkHeader. A remote attacker could send a malformed HTTP chunk size to exhaust system resources; Apache recommended upgrading to Tomcat 8.0.5, 7.0.53, 6.0.41, or later.
IBM X-Force reported CVE-2014-0096, an unauthenticated XML external entity vulnerability in Apache Tomcat's default XML processing that could allow remote attackers to disclose sensitive information. Apache recommended upgrading to Tomcat 8.0.5, 7.0.53, 6.0.41, or later, or applying a vendor update.
Red Hat replaced JBoss Data Grid 6.2.1 with version 6.3.0 in a Moderate-impact update that addressed multiple issues, including the JBoss Web request-smuggling flaw CVE-2014-0099. The update also remediated denial-of-service, audit-log exposure, XXE, and XML parser-hijacking issues.
Red Hat released updated JBoss EAP 6.2.4 packages for RHEL 5 and 6 to remediate four Moderate-impact JBoss Web vulnerabilities, including CVE-2014-0075, CVE-2014-0096, CVE-2014-0099, and CVE-2014-0119.
Red Hat released a Moderate-impact JBoss EAP 6.2.4 update addressing denial-of-service, HTTP request-smuggling, XXE, and XML-parser replacement flaws, including CVE-2014-0096 and CVE-2014-0099. Red Hat advised customers to apply the update and restart the JBoss server.
Red Hat issued a Moderate-impact security update for the Apache Tomcat 6 component in JBoss Web Server 2.0.1, fixing CVE-2014-0075, CVE-2014-0099, and CVE-2014-0096. Users were instructed to apply the update and restart JBoss Web Server.
Red Hat addressed the Apache Tomcat/JBoss Web chunked-transfer denial-of-service vulnerability CVE-2014-0075 in Red Hat JBoss BPM Suite 6.0.3 through advisory RHSA-2015:0234.
Red Hat addressed the Tomcat/JBoss Web DefaultServlet XXE vulnerability, CVE-2014-0096, in Red Hat JBoss BRMS 6.0.3 through advisory RHSA-2015:0235.
IBM published a security bulletin identifying IBM QRadar as affected by Apache Tomcat vulnerabilities CVE-2014-0075, CVE-2014-0095, CVE-2014-0096, CVE-2014-0099, and CVE-2014-0119. The provided material does not specify affected versions or remediation guidance.
Red Hat stated that JBoss Web in JBoss Enterprise Application Platform 5 was affected by CVE-2014-0099 and rated the impact Moderate. It said no future fix was planned because EAP 5 was in Phase 2 maintenance support, which received only Critical and Important updates.
Red Hat released JBoss Operations Network 3.2.3 to replace version 3.2.2, with a Moderate security-impact rating. The update remediated JBoss Web flaws CVE-2014-0075 and CVE-2014-0099; users were advised to back up installations and upgrade.
Mageia published advisory MGASA-2014-0268 for updated Tomcat and Tomcat 6 packages that fix security vulnerabilities.
Fedora 21's stable repository received tomcat-7.0.59-1.fc21, which included the fix for the CVE-2014-0099 Content-Length integer-overflow request-smuggling vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
exchange.xforce.ibmcloud.com
Open sourceexchange.xforce.ibmcloud.com
Open sourceexchange.xforce.ibmcloud.com
Open sourcerhn.redhat.com
Open sourceadvisories.mageia.org
Open sourceseclists.org
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.