Red Hat issued Important security updates across JBoss Enterprise Application Platform (EAP), Data Grid, A-MQ, SOA Platform, and Fuse to remediate Apache WSS4J and other component vulnerabilities. A key issue, CVE-2015-0226, left WS-Security deployments using PKCS#1 v1.5 XML Encryption exposed to a Bleichenbacher adaptive chosen-ciphertext attack: crafted messages could distinguish encrypted-key processing failures from message-data failures and create a decryption oracle. The advisories also addressed XML Signature wrapping, XML external entity expansion, CPU-exhaustion, authentication and authorization weaknesses, and the insecure default permissions of the local .jboss-cli-history file.
Affected EAP 6.4 systems on RHEL 6 and 7 were instructed to install updated packages, reconcile retained .rpmnew configuration files where applicable, and restart JBoss services. Red Hat also directed Data Grid 6.4.0 customers to upgrade to 6.4.1 and A-MQ 6.1.0 users to upgrade to 6.2.0; later SOA Platform and Fuse releases additionally fixed severe JGroups, BeanShell, Groovy, Spring, Camel, Shiro, and Bouncy Castle issues, including remote code execution, cluster-message spoofing, denial of service, information disclosure, and private-key exposure risks.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
RHSA-2016:1376 updated JBoss SOA Platform 5.3.1 to address five vulnerabilities, including JGroups authorization bypass CVE-2016-2141 and remote-code-execution risks in Groovy and BeanShell deserialization. The advisory also remediated the Apache WSS4J Bleichenbacher-related flaw CVE-2015-0226.
Red Hat issued RHSA-2015:0847 for RHEL 6 and RHSA-2015:0848 for RHEL 7, both Important updates for JBoss EAP 6.4.0. The updates addressed WSS4J, PicketLink, Tomcat mod_jk, and insecure JBoss CLI history-file permissions vulnerabilities.
Red Hat made the low-severity CVE-2014-3586 issue public. The flaw allowed local users to read otherwise inaccessible information from CLI history files created with insecure default permissions.
Pedro Igor marked PLINK-680 resolved after PicketLink flaws allowed SAML assertions intended for one service provider to be replayed to another and accepted Responses with arbitrary Destination URIs. Red Hat remediated CVE-2015-0277 in JBoss EAP 6.4 and JBEAP 6.4.z updates for RHEL 5, 6, and 7.
Vasyl Kaigorodov reported CVE-2015-0227, in which XML wrapping attacks could bypass WSS4J's requireSignedEncryptedDataElements protection. Apache corrected the issue in WSS4J 1.6.17 and 2.0.2.
Red Hat released the Important-rated JBoss Fuse 6.3 update for JBoss Fuse 6.2.1. It addressed seven CVEs across JGroups, BeanShell, Apache Shiro, Spring, Apache Camel, and Bouncy Castle, including remote-code-execution, denial-of-service, unauthorized-access, and private-key-extraction risks.
Red Hat released the Important-rated JBoss A-MQ 6.2.0 update for version 6.1.0. It remediated SSL hostname-verification, HawtIO authorization, WSS4J XML Encryption and signature-validation, and PKIX trust-handling flaws.
Red Hat released JBoss Data Grid 6.4.1 to replace version 6.4.0, rated the update Important, and advised users to upgrade. It fixed flaws in Apache WSS4J, Xerces-J, RESTEasy, and JBoss Weld, including XML external entity, CPU-exhaustion, signed-request modification, and conversation-data exposure risks.
Apache corrected CVE-2015-0226 in Subversion revision 1621329. The flaw could expose a decryption oracle in WS-Security uses of PKCS#1 v1.5 key transport, enabling symmetric-key plaintext recovery.
Red Hat remediated the insecure JBoss CLI history-file permissions flaw in JBoss Portal 6.2.0 through RHSA-2015:1009. JON 3.3.4 also addressed the issue through its rebase to EAP 6.4.3.
Red Hat closed Bugzilla 1181838 as ERRATA after determining that RHSA-2015:0218 resolved the reported issue. The remediation required upgrading WSS4J to 1.6.17.SP1-redhat-1 for RHEL 7.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.