First published: Mon Aug 22 2016(Updated: )
The fix for <a href="https://access.redhat.com/security/cve/CVE-2016-3737">CVE-2016-3737</a> in JON 3.3.6 was deemed to be incomplete. While we included a documentation fix in the installation guide which explained how to mitigate the issue, we provided misleading information in the security advisory for JON 3.3.6, that it was fixed by that update, which was not correct. To fix this issue, you need to configure SSL authentication for the JON Server/Agent communication. Please see the documentation for details on how to do that: <a href="https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html">https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html</a> It is not feasible to correct this issue with a code change as client SSL certificates need to be created in order to support client authentication. The Administration and Configuration guide notes how to mitigate this through the creation of certificates to support SSL authentication. This mitigation is the best way to correct this issue and, as a result, we will not be releasing any patches to correct the issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Operations Network | =3.0 | |
Red Hat JBoss Operations Network | =3.0.1 | |
Red Hat JBoss Operations Network | =3.1 | |
Red Hat JBoss Operations Network | =3.1.1 | |
Red Hat JBoss Operations Network | =3.1.2 | |
Red Hat JBoss Operations Network | =3.1.4 | |
Red Hat JBoss Operations Network | =3.2.0 | |
Red Hat JBoss Operations Network | =3.2.1 | |
Red Hat JBoss Operations Network | =3.2.2 | |
Red Hat JBoss Operations Network | =3.2.3 | |
Red Hat JBoss Operations Network | =3.3.1 | |
Red Hat JBoss Operations Network | =3.3.2 | |
Red Hat JBoss Operations Network | =3.3.3 | |
Red Hat JBoss Operations Network | =3.3.4 | |
Red Hat JBoss Operations Network | =3.3.5 | |
Red Hat JBoss Operations Network | =3.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6330 has a medium severity rating due to the incomplete fix for a prior vulnerability.
To mitigate CVE-2016-6330, follow the updated documentation and apply the recommended configurations outlined in the security advisor.
CVE-2016-6330 affects Red Hat JBoss Operations Network versions 3.0 through 3.3.6.
Yes, a patch is available as part of the security updates for Red Hat JBoss Operations Network.
Ignoring CVE-2016-6330 may leave the system vulnerable to exploitation via an incomplete fix for a previously reported issue.