Red Hat issued Moderate-security updates for JBoss Enterprise Application Platform (EAP) 6.2.2, JBoss Web Server 2.0.1, and RHEL tomcat6 packages to address CVE-2013-4286, an HTTP request-processing flaw involving conflicting Content-Length and chunked-transfer headers. Successful exploitation could cause web-cache poisoning, cross-site scripting, or disclosure of data from other requests. The related Tomcat updates also remediate CVE-2013-4322, a resource-exhaustion denial of service in chunked-request processing, and CVE-2014-0050, an infinite-loop denial of service in embedded Apache Commons FileUpload; Tomcat 6 updates additionally address CVE-2014-0033, a URL-rewriting issue that could facilitate session hijacking.
Red Hat instructed affected EAP, JBoss Web Server, and Tomcat administrators to install the supplied backported packages and restart the relevant server processes, preserving and merging local configuration changes where necessary. Separate JBoss middleware releases also delivered broader security fixes: JBoss Fuse 6.1.0 addressed issues including XML signature spoofing, XXE, authentication downgrade, denial of service, and credential exposure, while JBoss BRMS 6.0.3 corrected Important-severity flaws including potential remote code execution through Xalan-Java secure-processing bypasses, OpenSAML XXE, excessive Java Security Manager permissions, and plaintext request-parameter logging.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2014:0526 with backported tomcat7 fixes for JBoss Web Server 2.0.1 on RHEL 5 and 6. It remediated CVE-2013-4286, CVE-2013-4322, and CVE-2014-0050.
Red Hat released Moderate-severity RHSA-2014:0525 with updated tomcat6 packages for JBoss Web Server 2.0.1 on RHEL 5 and 6. The update fixed CVE-2013-4286, CVE-2013-4322, CVE-2014-0033, and CVE-2014-0050.
Red Hat issued Moderate-severity advisory RHSA-2014:0458 and Roll Up Patch 1 for Red Hat JBoss Data Virtualization 6.0.0. The cumulative patch remediated CVE-2013-4286 in JBoss Web/Tomcat and included additional non-security bug fixes.
Red Hat issued Moderate-severity RHSA-2014:0429 with backported tomcat6 fixes for RHEL 6. It remediated CVE-2013-4286, CVE-2013-4322, and CVE-2014-0050, covering request smuggling-related impact and denial-of-service conditions.
Red Hat published Moderate-severity advisory RHSA-2014:0343 for JBoss EAP 6.2.2 on RHEL 5. The update fixed CVE-2013-4286 HTTP request handling and CVE-2014-0093 Java Security Manager permission enforcement flaws.
The CVE-2013-4286 record for a Moderate-severity Tomcat and JBoss Web HTTP request-handling flaw was published. The vulnerability could allow unauthenticated attackers to poison web caches, conduct XSS attacks, or access sensitive information from other requests.
Red Hat released an Important-security-impact update of Apache Tomcat 7 for Red Hat Enterprise Linux 7. The backported patches remediated CVE-2014-0186, CVE-2013-4286, and CVE-2013-4322; administrators were advised to restart Tomcat after updating.
Red Hat released an Important-security-impact update for JBoss Operations Network 3.2.1 that remediated CVE-2014-0114, a Struts 1 ActionForm flaw that could enable ClassLoader manipulation and possible remote code execution, and CVE-2013-4286 in JBoss Web request handling. Red Hat advised users to back up installations and apply the Customer Portal update.
Red Hat released Important-severity JBoss BRMS 6.0.3 as a replacement for version 6.0.2. The update fixed vulnerabilities including Xalan-Java secure-processing bypasses, OpenSAML XXE, JBoss permission issues, HawtJNI library replacement, MSC registry access, and plaintext audit logging of request parameters.
Red Hat released a Moderate-impact Apache Tomcat 6 update for JBoss Web Server 2.0.1. It addressed CVE-2013-4286, CVE-2013-4322, CVE-2014-0033, and CVE-2014-0050.
Red Hat released a Moderate-impact Apache Tomcat 7 update for JBoss Web Server 2.0.1. The update fixed CVE-2013-4286, CVE-2013-4322, and CVE-2014-0050 and required a JBoss Web Server restart after installation.
Red Hat made JBoss Fuse 6.1.0, a minor update to version 6.0.0, available through the Customer Portal and rated it Moderate impact. The release addressed vulnerabilities across Apache Santuario, Hadoop, Spring, Commons FileUpload, HawtJNI, and ZooKeeper.
Red Hat remediated CVE-2014-0033 for JBoss Enterprise Web Server 2.0.1 through RHSA-2014:0528. The Tomcat 6 regression allowed URL-supplied session IDs despite disableURLRewriting being enabled; JBoss Web and RHEL 6 Tomcat were unaffected.
Red Hat released Moderate-impact advisory RHSA-2014:0345 for JBoss Enterprise Application Platform 6.2.2, remediating CVE-2013-4286 in JBoss Web and CVE-2014-0093 in Java Security Manager permission handling. Red Hat advised Customer Portal users to back up installations, apply the update, and restart the JBoss server process.
Red Hat addressed CVE-2013-4286 in JBoss Enterprise Application Platform 6.2 and 6 for Red Hat Enterprise Linux 6 through advisory RHSA-2014:0344.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
29 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcemandriva.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.