Red Hat released moderate-severity updates for JBoss Enterprise Application Platform (EAP) 6.3.3/6.3.z on Red Hat Enterprise Linux 5, 6, and 7, addressing five flaws in RESTEasy XML handling, RBAC, JacORB, security-domain selection, and Weld conversation-state processing. The most externally reachable issue, CVE-2014-7839, allowed XML external entity expansion through a RESTEasy endpoint, potentially exposing files readable by the application-server account.
The updates also remediate CVE-2014-7849, through which an authenticated RBAC Maintainer could alter a limited set of protected attributes, and CVE-2014-7853, which exposed sensitive security-domain data to authenticated users with incorrectly sufficient attribute permissions. Organizations should apply the relevant RHSA-2015:0215, RHSA-2015:0216, or RHSA-2015:0218 packages—including the RHEL 5 component updates—and restart JBoss server processes to activate the fixes.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat released the Moderate-severity RHSA-2015:0218 update for JBoss EAP 6.3.3 on RHEL 7. It remediated CVE-2014-7839, CVE-2014-7849, CVE-2014-7853, CVE-2014-7827, and CVE-2014-8122; administrators were instructed to restart JBoss after installation.
Red Hat issued the Moderate-severity RHSA-2015:0217 update for JBoss EAP 6.3.3 on RHEL 6, replacing EAP 6.3.2. It remediated CVE-2014-7839, CVE-2014-7849, CVE-2014-7853, CVE-2014-7827, and CVE-2014-8122; administrators were instructed to restart JBoss after installation.
Red Hat released the Moderate-severity RHSA-2015:0216 update for JBoss EAP 6.3.3 on RHEL 5. The update addressed five flaws, including RESTEasy XXE, RBAC and JacORB authorization issues, a security-domain fallback issue, and Weld conversation-state information disclosure.
Red Hat issued RHSA-2015:0215 to fix CVE-2014-7849 and CVE-2014-7853 in JBoss Enterprise Application Platform 6.3.
Arun Babu Neelicattu reported CVE-2014-7853, in which the JacORB subsystem used an incorrect sensitivity classification for the security-domain attribute, potentially exposing sensitive information to certain authenticated users.
Arun Babu Neelicattu reported CVE-2014-7849, a JBoss EAP RBAC flaw that could let an authenticated Maintainer add, modify, or undefine a limited set of protected attributes.
Red Hat closed Bugzilla issue 1275307, concerning an upgrade of ironjacamar-eap6 to 1.0.34.Final-redhat-1 for RHEL 5 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:2538 for updated files and remediation information.
Red Hat closed Bugzilla issue 1275316, concerning an upgrade of jbossweb to 7.5.12.Final-redhat-1 for RHEL 5 RPMs, with an ERRATA resolution. The notice directed users to RHSA-2015:2538 for updated files and remediation information.
Red Hat closed Bugzilla issue 1195923, concerning an upgrade of jboss-dmr to 1.2.2.Final-redhat-1 for RHEL 7 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla issue 1188937, concerning an upgrade of RESTEasy to 2.3.10.Final-redhat-1 for RHEL 6 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0847 for updated files and remediation information.
Red Hat closed Bugzilla issue 1182979, concerning an upgrade of the GlassFish JSF 1.2/Mojarra component for EAP 6, with an ERRATA resolution. The notice cited RHSA-2015:0847 for updated files and remediation information, without identifying the underlying vulnerability.
Red Hat closed Bugzilla issue 1179829, concerning an upgrade of jboss-jsp-api_2.2_spec to 1.0.2.Final-redhat-1 for RHEL 6 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0847 for updated files and remediation information.
Red Hat closed Bugzilla bug 1195921, concerning an upgrade of jboss-dmr to 1.2.2.Final-redhat-1 for RHEL 6 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0847 for updated files and remediation information.
Red Hat closed Bugzilla issue 1179831, concerning an upgrade of jboss-jsp-api_2.2_spec to 1.0.2.Final-redhat-1 for RHEL 7 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla issue 1179838, concerning an upgrade of jboss-vfs2 to 3.2.9.Final-redhat-1 for RHEL 7 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla issue 1182995, concerning an upgrade of jboss-weld-1.1-api to 1.1.0.Final-redhat-6 for RHEL 7 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla issue 1182997, concerning an upgrade of weld-cdi-1.0-api to 1.0.0.SP4-redhat-5 for RHEL 7 RPMs, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla bug 1182985, concerning an upgrade of xml-commons-resolver-eap6 to 1.2.0.redhat-10, with an ERRATA resolution. The notice cited RHSA-2015:0848 for updated files and remediation information.
Red Hat closed Bugzilla bug 1188939 with an ERRATA resolution, stating that a recent security advisory should resolve the reported problem. The notice directs users to RHSA-2015:0848 for updated files and remediation information, but does not identify the affected vulnerability or product.
Red Hat closed the CVE-2014-7827 flaw tracker after all associated trackers had been fixed, resolved, or had errata issued.
Red Hat remediated the RESTEasy DocumentProvider XXE flaw CVE-2014-7839 through updates for JBoss EAP on RHEL 6, JBoss Data Virtualization, Data Grid, BPM Suite, BRMS, and Portal Platform. Red Hat stated that the unsupported Web Framework Kit would not receive a future fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
issues.jboss.org
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.