Red Hat released JBoss Enterprise Application Platform (EAP) 6.2.1 to replace EAP 6.2.0 and remediate three Moderate-impact vulnerabilities. CVE-2013-6440 affects OpenSAML/XMLTooling-J and allows externally supplied XML entities to be resolved, potentially enabling unauthenticated remote attackers to read files accessible to the application-server account and conduct further XXE attacks. CVE-2013-4517 affects Apache Santuario XML Security for Java, where DTD processing during XML transforms can exhaust memory and cause an OutOfMemoryError. CVE-2014-0018 permits deployed code running under a Java Security Manager to access the Modular Service Container service registry without required permission checks and alter JBoss internal server state.
The fixes were delivered through RHSA-2014:0170 for RHEL 5, RHSA-2014:0171 for RHEL 6, and RHSA-2014:0172 for Customer Portal distributions. Organizations operating EAP 6.2.0 should upgrade to EAP 6.2.1, back up installations and deployed applications, review and merge locally modified configuration files preserved as .rpmnew where applicable, and restart the JBoss server process after installation.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2014:1725, RHSA-2014:1726, and RHSA-2014:1728 to remediate the Apache Santuario XML Security denial-of-service flaw CVE-2013-4517 in JBoss EAP 5/5.2 and JBoss Enterprise Web Platform 5 for RHEL 5 and RHEL 6.
Red Hat issued RHSA-2014:1290 for JBoss BRMS 6.0 and RHSA-2014:1291 for JBoss BPMS 6.0, remediating CVE-2014-0018 in both products.
Red Hat issued RHSA-2014:0452 to fix CVE-2013-6440 in affected Fuse ESB Enterprise, Fuse Management Console, and Fuse MQ Enterprise 7.1.0 products.
Red Hat issued Moderate-security advisory RHSA-2014:0195 for Red Hat JBoss Portal 6.1.1, replacing version 6.1.0. The update fixed the OpenSAML XXE vulnerability CVE-2013-6440 and the Apache Santuario XML Security denial-of-service vulnerability CVE-2013-4517.
CVE-2014-0018 was publicly published, documenting that JBoss EAP 6.2.0 and WildFly running under a security manager did not properly restrict deployed-code access to the MSC service registry. A local user could use a crafted deployment to modify the affected server.
Red Hat released JBoss EAP 6.2.1 to replace EAP 6.2.0, rated the update Moderate impact, and fixed CVE-2013-6440, CVE-2013-4517, and CVE-2014-0018. Administrators were instructed to apply the update and restart the JBoss server process.
Red Hat issued RHSA-2014:0171, a Moderate-security update for JBoss EAP 6.2.1 on RHEL 6 replacing EAP 6.2.0. The update fixed CVE-2013-6440, CVE-2013-4517, and CVE-2014-0018.
Red Hat issued a Moderate-security update providing JBoss EAP 6.2.1 for RHEL 5, replacing EAP 6.2.0. It remediated the OpenSAML XXE flaw CVE-2013-6440, the Apache Santuario denial-of-service flaw CVE-2013-4517, and CVE-2014-0018.
Arun Babu Neelicattu reported CVE-2014-0018, involving unchecked access to the Modular Service Container service registry by deployed code when JBoss EAP runs under a Java Security Manager.
Red Hat addressed the OpenSAML/XMLTooling-J XXE vulnerability CVE-2013-6440 in JBoss Fuse Service Works 6.0.0 through RHSA-2014:1995.
Red Hat addressed CVE-2014-0018 in JBoss Fuse Service Works 6.0.0 through RHSA-2014:1995 and in JBoss Portal 6.2.0 through RHSA-2015:1009. These product-specific fixes were not included in the existing timeline.
Red Hat issued RHSA-2014:1290 to remediate the affected xmltooling component and CVE-2013-6440 in Red Hat JBoss BRMS 6.0.
Red Hat issued RHSA-2014:1291 to remediate the affected xmltooling component and CVE-2013-6440 in Red Hat JBoss BPMS 6.0.
Red Hat required an upgrade to HornetQ to resolve Bugzilla issue 1053215 and verified the fix in a CR3 build. The issue was closed as ERRATA, with updated files referenced through RHSA-2014:0171.
Red Hat upgraded JBoss Marshalling to jboss-marshalling-1.4.3-1.Final_redhat_1.1.ep6.el6, sourced from commit 2e75ea5c71ba7ec6f4315e9e78fe642bfc41949f. The update was verified in a CR3 build and Bugzilla issue 1053230 was closed as ERRATA, with updated files provided through RHSA-2014:0171.
Red Hat upgraded Weld Core to weld-core-1.1.17-1.Final_redhat_1.1.ep6.el6 from commit 1b99e8142ee55ff1280fe10538987eec1415c0c4. Bugzilla 1053778 was verified in a CR3 build and closed as ERRATA, with updated files provided through RHSA-2014:0171.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
30 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.