Red Hat issued Important-security updates across JBoss BPM Suite, JBoss BRMS, JBoss Fuse Service Works, and JBoss Data Grid, addressing flaws that could lead to remote or authenticated arbitrary Java code execution. Affected components included Xalan-Java XSLT secure-processing bypasses, insecure XStream XML deserialization, Apache Camel XSLT handling, and MVEL/JBoss Rules expression evaluation; several releases also corrected XML external entity (XXE) weaknesses in OpenSAML, Camel, and RESTEasy.
The updates additionally fixed Java Security Manager policy failures that could grant deployed applications java.security.AllPermission, JBoss MSC service-registry access-control issues, HawtJNI temporary-file risks, plaintext authentication-parameter logging, Smack XMPP spoofing, WebSocket memory-exhaustion denial of service, and TLS CBC padding-oracle exposure. Red Hat instructed customers to back up installations, stop the JBoss Application Server, apply the applicable upgraded release or roll-up patch, and restart services; organizations using rule-authoring or externally exposed environments were advised to retain Java Security Manager sandboxing for MVEL evaluation.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2019:1545 to remediate CVE-2016-2510 in the camel component of Red Hat Fuse 7.3.1. The BeanShell deserialization vulnerability could allow unauthenticated remote code execution when a vulnerable application deserialized a malicious object chain.
Red Hat issued RHSA-2016:0540, an Important-security-impact update replacing JBoss BRMS 6.2.1 with 6.2.2. The release fixed CVE-2016-2510, a BeanShell deserialization flaw that could allow remote attackers to execute arbitrary code with affected application permissions.
Andrej Nemec reported Red Hat Bug 1310647 for CVE-2016-2510, a high-severity BeanShell (bsh2) unsafe-deserialization flaw. The issue could permit arbitrary shell-command execution when BeanShell is on an application's classpath and untrusted data is deserialized through Java serialization or XStream.
Red Hat issued Critical advisory RHSA-2015:2502 for JBoss Data Grid 6.4.1 and 6.5.1, providing updated Apache Commons Collections packages for CVE-2015-7501. The unsafe deserialization flaw could let a remote attacker execute arbitrary code with the affected application's privileges.
Red Hat issued RHSA-2014:1059, an Important security update for the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2. The update fixed XStream arbitrary XML deserialization (CVE-2013-7285) and a Xalan-Java secure-processing bypass that could enable remote code execution (CVE-2014-0107).
Red Hat issued RHSA-2014:0374, an Important update replacing JBoss Data Grid 6.2.0 with version 6.2.1. The release fixed XStream arbitrary XML deserialization (CVE-2013-7285) and the Tomcat HTTP request-processing flaw CVE-2013-4286.
Red Hat published RHSA-2014:0344, a Moderate-severity update for JBoss Enterprise Application Platform 6.2.2 on RHEL 6. It fixed CVE-2013-4286, an HTTP request-handling flaw with cache-poisoning, XSS, and data-disclosure risk, and CVE-2014-0093, which granted deployed applications AllPermission.
Red Hat released JBoss A-MQ 6.2.1 as an Important-security-impact update for version 6.2.0. It fixed Apache Commons Collections and Groovy unsafe-deserialization code-execution flaws (CVE-2015-7501 and CVE-2015-3253) and stored JavaScript execution in the A-MQ console via crafted queue names (CVE-2015-5181).
Red Hat released an Important-security-impact cumulative Rollup Patch 1 of 2014 for JBoss BRMS 5.3.1. The patch fixed XStream arbitrary XML deserialization (CVE-2013-7285) and a Xalan-Java secure-processing bypass that could enable remote code execution (CVE-2014-0107).
Red Hat released an Important-security-impact R1 Patch 3 update for Fuse ESB Enterprise and Fuse MQ Enterprise 7.1.0. It fixed XStream and Apache Camel XSLT remote-code-execution flaws, OpenSAML and Camel XXE flaws, and an Apache Commons FileUpload denial-of-service issue.
Red Hat released Roll Up Patch 3 for JBoss Fuse Service Works 6.0.0, a cumulative update rated Important for security impact. The patch fixed six vulnerabilities including CVE-2014-0107, CVE-2013-6440, CVE-2014-0093, CVE-2013-2035, CVE-2014-0018, and CVE-2014-0058.
Red Hat released an Important-security-impact Roll Up Patch 1 for JBoss Fuse Service Works 6.0.0. The cumulative update fixed Apache Camel XSLT remote-code-execution and XXE flaws, the JBoss Web request-handling flaw CVE-2013-4286, and the Apache Commons FileUpload denial-of-service flaw CVE-2014-0050.
Red Hat released JBoss BPM Suite 6.0.3 to replace version 6.0.2 and rated the update Important. It remediated six vulnerabilities affecting Xalan-Java, OpenSAML, Java Security Manager permissions, HawtJNI, the JBoss MSC service registry, and security-audit logging.
Red Hat released JBoss BRMS 6.0.3 as an Important-security-impact replacement for 6.0.2. The update fixed six flaws, including Xalan-Java remote-code-execution risk, OpenSAML XXE, excessive Java Security Manager permissions, HawtJNI library replacement, JBoss MSC access, and plaintext authentication logging.
Red Hat released JBoss BRMS 6.0.2, replacing version 6.0.1, with an Important security-impact rating. It fixed the Xalan-Java secure-processing bypass CVE-2014-0107, two Smack XMPP spoofing flaws, and the WebSocket memory-exhaustion denial-of-service flaw CVE-2014-0193.
Red Hat released JBoss BRMS 6.0.1 as an Important-security-impact replacement for 6.0.0. It fixed the same MVEL/JBoss Rules code-execution issue, XStream deserialization, Apache Camel XSLT code-execution and XXE flaws, RESTEasy XXE flaws, and the Bouncy Castle CBC padding-oracle issue.
Red Hat released JBoss BPM Suite 6.0.1 as an Important-security-impact replacement for 6.0.0. The update addressed arbitrary code execution through MVEL/JBoss Rules expressions, unsafe XStream deserialization, Apache Camel XSLT flaws, RESTEasy XXE issues, and a Bouncy Castle TLS CBC padding-oracle weakness.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
24 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.