Red Hat released RHSA-2015:0846 and RHSA-2015:0849 for JBoss Enterprise Application Platform (EAP) 6.4, addressing important flaws in PicketLink, Apache WSS4J, mod_jk, and mod_cluster. The PicketLink defects, CVE-2015-0277 and CVE-2015-6254, allowed remote attackers to authenticate as victim users because SAML assertion Audience conditions and SAML Response Destination attributes were not properly validated.
The updates also remediate CVE-2015-0298, in which crafted Mod-Cluster Management Protocol messages could inject arbitrary JavaScript into the mod_cluster manager interface when sent from an authorized network, and CVE-2014-8111, where JkUnmount exclusions could be ignored after matching parent JkMount rules, potentially exposing protected artifacts. Red Hat advised customers to install the updated packages, merge any local configuration customizations, apply prerequisite errata, and restart JBoss server processes.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued an Important update for JBoss Web Server 2.1.0 on RHEL 5, 6, and 7, fixing the mod_cluster JavaScript-injection flaw CVE-2015-0298 and mod_jk access-control flaw CVE-2014-8111. The advisory supplied updated mod_cluster-native and mod_jk packages and instructed users to restart JBoss Web Server after updating.
Red Hat issued RHSA-2015:1177 for JBoss A-MQ 6.2, fixing the Apache WSS4J XML Signature wrapping vulnerability CVE-2015-0227. The flaw could allow an unauthenticated remote attacker to modify content in a signed request by bypassing the requireSignedEncryptedDataElements setting.
Red Hat issued RHSA-2015:0849 to fix affected JBoss Enterprise Application Platform 6.4 components, including the PicketLink issues CVE-2015-0277 and CVE-2015-6254 and the mod_jk issue CVE-2014-8111.
Red Hat issued Important advisory RHSA-2015:0847 for JBoss EAP 6.4.0 on RHEL 6, updating packages to address flaws including CVE-2015-0226, CVE-2015-0227, CVE-2014-8111, CVE-2015-0277, and CVE-2014-3586. Administrators were instructed to apply the update, manually merge any required .rpmnew configuration changes, and restart JBoss server processes.
Red Hat issued an Important update for JBoss EAP 6.4.0 and 6.4.z on RHEL 5, addressing vulnerabilities including CVE-2015-0226, CVE-2015-0227, CVE-2014-8111, CVE-2015-0277, CVE-2014-3586, CVE-2015-0298, and CVE-2015-6254. Administrators were instructed to install the packages and restart JBoss server processes.
Red Hat published the CVE record for an Important PicketLink authentication vulnerability involving failure to validate that a SAML Response Destination attribute matched the receiving location. The flaw could enable remote login to a victim account.
Red Hat published the CVE record for an Important PicketLink authentication-bypass flaw in which Service Providers did not evaluate the Audience condition of SAML assertions. The flaw could allow a remote attacker to log in to a victim account.
Red Hat marked JBoss JIRA issue PLINK-680 resolved and committed fixes to the PicketLink EAP 6.x branches for SAML AudienceRestriction and Response Destination validation flaws. The fixes addressed assertion replay across Service Providers and acceptance of responses delivered to an endpoint other than the specified Destination.
CVE-2015-0227 was published for an Apache WSS4J XML Signature wrapping vulnerability affecting versions before 1.6.17 and 2.x before 2.0.2. A remote attacker could bypass the requireSignedEncryptedDataElements configuration; the issue was addressed in WSS4J 1.6.17 and 2.0.2.
Red Hat issued RHSA-2015:1641 to address CVE-2015-0298, a mod_cluster Manager interface JavaScript-injection vulnerability exploitable through crafted MCMP messages, for affected JBoss Web Server 2 deployments on RHEL 5, 6, and 7.
The mod_cluster manager JavaScript-injection vulnerability CVE-2015-0298 was made public. An attacker on an authorized MCMP network could use crafted management-protocol messages to execute arbitrary JavaScript in the manager web interface.
Red Hat documented that ignored JkUnmount subtree rules in Apache mod_jk could expose restricted artifacts and rated CVE-2014-8111 Moderate. It identified fixes for JBoss EAP 6.4.z on RHEL 6 and 7 and JBoss Web Server 2.x, while stating several older products would not receive future fixes.
Red Hat closed Bugzilla issue 1188946 as ERRATA, directing users to RHSA-2015:0848 for remediation information and updated PicketLink bindings files for RHEL 7. Users whose issue persisted after applying the advisory were instructed to file a new bug report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
issues.jboss.org
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcecve.org
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.