Red Hat released Moderate-severity updates for Apache POI bundled with JBoss BRMS 6.0.3, JBoss BPM Suite 6.0.3, JBoss Data Virtualization 6.0.0, and JBoss Fuse Service Works 6.0.0. The updates remediate CVE-2014-3529, an XML external entity (XXE) vulnerability in OOXML parsing that could allow an attacker who supplies a crafted document to read files accessible to the application-server user and potentially perform further XXE attacks.
The releases also fix CVE-2014-3574, in which uncontrolled XML entity expansion in OOXML documents could exhaust CPU and memory, causing denial of service. Red Hat advised affected customers to install the applicable updates; deployments should be backed up and the JBoss Application Server stopped before installation. Fedora also shipped Apache POI 3.10.1 updates containing upstream fixes.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2014:1398 for JBoss Data Virtualization 6.0.0, remediating CVE-2014-3529 and CVE-2014-3574 in its Apache POI component.
Red Hat issued RHSA-2014:1399 for JBoss BPM Suite 6.0.3. The Moderate-severity update addressed the Apache POI XXE and unlimited entity-expansion vulnerabilities.
Red Hat issued RHSA-2014:1400, a Moderate-severity Apache POI security update for JBoss BRMS 6.0.3, fixing CVE-2014-3529 and CVE-2014-3574.
Red Hat published RHSA-2014:1370 for JBoss Fuse Service Works 6.0.0. The Moderate-severity update remediated CVE-2014-3529 and CVE-2014-3574.
Fedora published apache-poi-3.10.1-1.fc20 to the Fedora 20 stable repository, addressing the Apache POI OOXML XXE and entity-expansion vulnerabilities.
Red Hat addressed CVE-2014-3529 and CVE-2014-3574 in JBoss Portal 6.2.0 through RHSA-2015:1009. Red Hat determined JBoss Portal Platform was not exploitable by default unless a custom application processed user-supplied XML with its bundled Apache POI library.
Fedora published apache-poi-3.10.1-2.fc21 to the Fedora 21 stable repository for CVE-2014-3529.
Apache POI issued upstream source fixes for CVE-2014-3529, which allowed external-entity resolution in OOXML documents, and CVE-2014-3574, an unlimited entity-expansion denial-of-service flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.