Red Hat released Moderate-severity updates for JBoss Enterprise Application Platform (EAP) 6.2 on Red Hat Enterprise Linux 5 and 6, advancing deployments from version 6.2.3 to 6.2.4. The fixes address five vulnerabilities affecting Apache CXF and the JBoss JAX-RS implementation, including a SAML-token validation bypass, XML external entity (XXE) information disclosure, denial-of-service conditions, and potential plaintext credential exposure in a specific Apache CXF client-policy configuration.
The XXE flaw, tracked as CVE-2014-3481, affects RESTEasy applications using JBoss EAP default context parameters that did not explicitly disable external-entity expansion. Unauthenticated attackers could submit crafted XML to applications accepting XML input to read local files, cause server-side HTTP requests that bypass network restrictions, or exhaust CPU and memory. Red Hat advised affected administrators to install the updated EAP packages, restart JBoss, preserve customized configurations, and review and merge any generated .rpmnew configuration changes.

See affected versions and whether adversaries are exploiting it.
19 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2015:0236, providing Rollup Patch 2 for JBoss Fuse 6.1.0 and JBoss A-MQ 6.1.0. The update remediated CVE-2014-3623, a WSS4J/CXF SAML spoofing flaw, and CVE-2014-3625, a Spring Framework directory-traversal vulnerability.
Red Hat remediated the Apache WSS4J/CXF TransportBinding SAML SubjectConfirmation spoofing flaw, CVE-2014-3623, in JBoss EAP 6.3 through RHSA-2014:2019 and RHSA-2014:2020. RHSA-2014:2019 updated apache-cxf and wss4j components for RHEL 5, 6, and 7.
Fedora released wss4j-1.6.17-1.fc20 to the Fedora 20 stable repository to address CVE-2014-3623, the Apache WSS4J/CXF TransportBinding SAML SubjectConfirmation spoofing flaw.
Fedora released wss4j-1.6.17-1.fc21 to the Fedora 21 stable repository to address CVE-2014-3623, an Apache WSS4J/CXF TransportBinding spoofing flaw involving SAML SubjectConfirmation enforcement.
Red Hat released RHSA-2014:0895 to remediate CVE-2014-3481 in Red Hat JBoss Data Grid 6.3.
Red Hat remediated CVE-2014-0035 through RHSA-2014:0798 for JBoss EAP on RHEL 5. The flaw could cause Apache CXF clients using a Symmetric EncryptBeforeSigning password policy to transmit UsernameTokens in plaintext, allowing a man-in-the-middle attacker to obtain credentials.
Red Hat addressed CVE-2014-0110, in which malformed large SOAP messages could cause Apache CXF to write attacker-controlled residual data to /tmp and exhaust disk space. Fixes were provided for JBoss EAP through RHSA-2014:0797, RHSA-2014:0798, and RHSA-2014:0799, with later advisories covering JBoss Fuse/A-MQ, BPM Suite, BRMS, and Portal.
Red Hat addressed CVE-2014-0109, an Apache CXF flaw in which text/html POST requests to SOAP endpoints could cause excessive memory consumption and an out-of-memory denial of service. Fixes were included in JBoss EAP advisories RHSA-2014:0797 through RHSA-2014:0799 and later advisories for JBoss Fuse/A-MQ, BPM Suite, BRMS, and Portal.
Red Hat addressed CVE-2014-0034, in which cached Apache CXF SecurityTokenService validation could accept invalid SAML tokens, through RHSA-2014:0797, RHSA-2014:0798, and RHSA-2014:0799 for JBoss EAP 6.2 deployments.
Red Hat issued Moderate-severity advisory RHSA-2014:0799, updating JBoss EAP from 6.2.3 to 6.2.4 on RHEL 6. It remediated CVE-2014-3481 and four Apache CXF-related vulnerabilities; administrators were instructed to restart JBoss after installation.
Red Hat issued Moderate-severity advisory RHSA-2014:0798, updating JBoss EAP 6.2.3 to 6.2.4 on RHEL 5. The update addressed CVE-2014-3481 alongside Apache CXF SAML-validation, denial-of-service, and credential-exposure flaws.
Red Hat released RHSA-2014:0797 to fix CVE-2014-3481 in Red Hat JBoss Enterprise Application Platform 6.2.
Red Hat addressed the Apache CXF UsernameToken plaintext-exposure flaw, CVE-2014-0035, in JBoss Fuse/A-MQ 6.1.0 (RHSA-2014:1351), BPM Suite 6.1.0 (RHSA-2015:0851), BRMS 6.1.0 (RHSA-2015:0850), and JBoss Portal 6.2.0 (RHSA-2015:1009). The flaw could expose client usernames and passwords to a man-in-the-middle attacker under an EncryptBeforeSigning SymmetricBinding configuration.
Apache WSS4J issue WSS-511 proposed a default-enabled SAML validator property requiring assertions to include at least one recognized Subject Confirmation method: Bearer, Sender Vouches, or Holder of Key. Assertions lacking all such methods would be rejected.
Red Hat released RHSA-2015:0765 to remediate CVE-2014-3481 in Red Hat JBoss Data Virtualization 6.0.
Red Hat released RHSA-2015:0675 to fix CVE-2014-3481 in Red Hat JBoss Data Virtualization 6.1.
Red Hat addressed CVE-2014-3481 in JBoss Operations Network 3.3.0 through advisory RHSA-2014:1904.
Red Hat closed Bugzilla issue 1090473 with an ERRATA resolution after identifying RHSA-2014:0798 as containing the updated files. The issue, which required upgrading WSS4J to 1.6.15.redhat-1, was removed from CR2 and fixed in JBoss EAP 6.2.4 CR1.
Red Hat closed Bugzilla issue 1076134 with an ERRATA resolution, stating that RHSA-2014:0343 supplied updated files intended to resolve the issue. The upgrade was verified during EAP-6.2.2.CP-CR3 testing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
24 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.