Red Hat released JBoss BRMS 6.1.0 and JBoss BPM Suite 6.1.0 to replace version 6.0.3 and remediate 16 security vulnerabilities in the platforms and bundled components. The Important advisories cover SSL/TLS certificate and hostname-validation bypasses, SAML authentication and token-handling flaws, XML external entity (XXE) processing, denial-of-service conditions, information disclosure, and file-permission issues.
The fixes include XML-security hardening relevant to CVE-2013-4517, a Moderate Apache Santuario XML Security for Java flaw in which DTD processing during XML Transform operations could exhaust memory and cause an OutOfMemoryError, including under secure validation. Red Hat advised Customer Portal users to back up installations, stop the JBoss Application Server, upgrade from 6.0.3 to 6.1.0, and restart the server after installation.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Critical advisory RHSA-2015:2578 for JBoss BRMS 6.1.0, fixing CVE-2015-7501 in Apache Commons Collections. The deserialization flaw could allow a remote attacker to execute arbitrary code with the permissions of the affected application through a specially crafted class chain.
Red Hat issued RHSA-2015:0851 and released JBoss BPM Suite 6.1.0 as a replacement for 6.0.3. The Important-rated update fixed CVE-2013-4517 and 15 additional security vulnerabilities.
Red Hat issued RHSA-2015:0850 and released JBoss BRMS 6.1.0 as a replacement for 6.0.3. The Important-rated update fixed CVE-2013-4517 along with 15 other security vulnerabilities.
CVE-2014-3623 involved improper enforcement of security semantics for SAML SubjectConfirmation methods in Apache CXF security components and Apache WSS4J. Fixed versions include CXF 2.7.13 and 3.0.2, plus WSS4J 1.6.17 and 2.0.2.
Red Hat remediated low-impact CVE-2014-7827, in which JBossMappingManager could fall back to a default security domain and permit cross-domain authorization bypasses. Fixes were issued for JBoss EAP 6.3.z and included in JBoss BPM Suite and BRMS 6.1.0 updates.
Fedora 21 received xml-security-1.5.7-1.fc21 in its stable repository, providing an update addressing CVE-2013-4517.
Fedora 20 received xml-security-1.5.7-1.fc20 in its stable repository, providing an update addressing CVE-2013-4517.
Apache fixed CVE-2013-4517 in Santuario XML Security for Java 1.5.6 when secure validation is enabled. The corrected Santuario release was incorporated into Apache WSS4J 1.6.13 and Apache CXF 2.7.8 and 2.6.11.
Apache Santuario XML Security for Java processed DTDs during XML Transform operations even with secure validation enabled, allowing a remote attacker to exhaust memory and trigger an OutOfMemoryError denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcegithub.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.