Red Hat issued Important updates for JBoss Enterprise Application Platform, Enterprise Web Platform, BPM Suite, and BRMS to remediate SSL/TLS hostname-verification flaws in Apache HttpComponents, Apache CXF, and Jakarta Commons HttpClient. The vulnerabilities, CVE-2012-6153 and CVE-2014-3577, could let a man-in-the-middle attacker use a specially crafted X.509 certificate to impersonate a trusted SSL server. The defects stemmed from incomplete prior hostname-verification remediation and incorrect extraction of hostnames from certificate subject Common Name fields.
Affected deployments include JBoss EAP 5.2 and 6.3, Enterprise Web Platform 5.2, and roll-up patch releases for JBoss BPM Suite and BRMS 6.0.3 across supported Red Hat Enterprise Linux versions. Administrators should apply the applicable Red Hat errata or roll-up patches, back up installations and preserve customized configurations where required, then restart the JBoss server process; BPM Suite and BRMS installations should be stopped before patching.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2016:1931, Rollup Patch 4 for JBoss Fuse and JBoss A-MQ 6.2.1. The update fixed CVE-2014-3577 in Apache HttpComponents Client and Apache CXF, preventing SSL-server spoofing by a man-in-the-middle attacker using a crafted X.509 certificate.
Red Hat issued Important-rated RHSA-2014:2019 for JBoss EAP 6.3.2 on RHEL 5, 6, and 7. Updated Apache CXF and WSS4J packages fixed CVE-2012-6153, CVE-2014-3577, and CVE-2014-3623, including a SAML authentication spoofing risk affecting WSS4J-secured web-service endpoints.
Red Hat issued RHSA-2014:1834, an Important update for JBoss EAP 5.2.0 deployments on RHEL 4, 5, and 6. The updated Apache CXF packages fixed CVE-2012-6153 and CVE-2014-3577.
Red Hat published RHSA-2014:1833, an Important security update for JBoss Enterprise Web Platform 5.2.0 on RHEL 4, 5, and 6. The Apache CXF update addressed CVE-2012-6153 and CVE-2014-3577, which enabled SSL-server spoofing in a man-in-the-middle position.
Apache CXF committed a refactor of CertificateHostnameVerifier.getCNs in the 3.0.x-fixes branch. The change replaced comma-based certificate-subject parsing with RFC 2253 parsing through X500Principal and LDAP APIs to extract CN attributes safely.
Red Hat issued RHSA-2014:1321, an Important update for JBoss EAP 5.2.0 on RHEL 4, 5, and 6. Updated Jakarta Commons HttpClient and JBoss Seam packages fixed CVE-2012-6153 and CVE-2014-3577.
Red Hat released RHSA-2014:1320, an Important update for JBoss Enterprise Web Platform 5.2.0 on RHEL 4, 5, and 6. It remediated CVE-2012-6153 and CVE-2014-3577 in HttpClient hostname verification.
Red Hat issued Important-rated RHSA-2014:1166 for Jakarta Commons HTTPClient packages in RHEL 5, 6, and 7. The backported update fixed CVE-2014-3577, preventing man-in-the-middle SSL-server spoofing through a crafted X.509 certificate subject Common Name.
Red Hat issued RHSA-2014:1162, an Important update for JBoss EAP 6.3.0 on RHEL 5, 6, and 7. The update fixed CVE-2012-6153 and CVE-2014-3577, which could let a man-in-the-middle attacker spoof an SSL server using a crafted X.509 certificate.
CVE-2012-6153 was published for an SSL/TLS hostname-verification flaw in Apache Commons HttpClient before 4.2.3. The incomplete fix for CVE-2012-5783 allowed man-in-the-middle SSL-server spoofing using a crafted certificate with a common name embedded outside the CN field.
Red Hat issued RHSA-2014:1098, an Important security update for devtoolset-2-httpcomponents-client in Red Hat Developer Toolset 2 on RHEL 6. The backported update fixed CVE-2012-6153, which could allow a man-in-the-middle attacker using a crafted X.509 certificate to spoof an SSL server.
Red Hat closed Bugzilla 1181750 as ERRATA and directed users to RHSA-2015:0218 for updated Apache CXF files and remediation information for RHEL 7. Users for whom the update did not resolve the issue were advised to file a new bug report.
Red Hat closed Bugzilla 1181748 as ERRATA, stating that a recent security advisory resolved the issue. Users were directed to RHSA-2015:0217 for updated Apache CXF files for RHEL 6.
Red Hat identified HttpComponents Client in JBoss Data Grid 6 and JBoss Data Virtualization 6, plus ModeShape Client in Data Virtualization 6, as affected by CVE-2014-3577. Red Hat stated exploitation was not known to be possible in supported scenarios and that a future update might address the issue.
Red Hat closed Bugzilla 1093784 as ERRATA after fixing an oVirt Engine/RHEV-M REST API regression that caused Apache to remove HTTP Expect headers and VM operations requiring synchronous completion to run asynchronously. The fix added X-Ovirt-Expect support, with clients advised to send both headers for compatibility; updated files were referenced in RHSA-2015:0158.
Red Hat issued Important-rated RHSA-2015:0158 for Red Hat Enterprise Virtualization Manager 3.5.0 on Red Hat Virtualization 3.5 for x86_64. The update fixed SSL hostname-verification flaws CVE-2012-6153 and CVE-2014-3577, plus oVirt REST API CSRF (CVE-2014-0151) and missing HttpOnly cookie flags in the web administration interface (CVE-2014-0154).
Red Hat issued Important-rated errata for CVE-2014-3577 across additional products, including Red Hat Software Collections 1, RHEL 7, JBoss EAP/Web Platform variants, and later updates for multiple JBoss, OpenShift, and Red Hat platform products. The flaw allowed a man-in-the-middle attacker to spoof an SSL server by abusing incorrect extraction of a Common Name embedded in a crafted certificate subject.
Red Hat released Roll Up Patch 1 for JBoss BPM Suite 6.0.3, rated Important. The patch addressed CVE-2012-6153 and CVE-2014-3577 in the affected HttpClient and Apache CXF hostname-verification functionality.
Red Hat released Roll Up Patch 1 for JBoss BRMS 6.0.3, rated Important. The cumulative update fixed CVE-2012-6153 and CVE-2014-3577, along with other bugs and enhancements.
Apache announced CVE-2014-3577, a hostname-verification vulnerability in Apache HttpComponents client that was susceptible to man-in-the-middle attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
30 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcegithub.com
Open sourceaccess.redhat.com
Open sourcemail-archives.apache.org
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.