RHSA-2008:0158: Moderate: JBoss Enterprise Application Platform security update
JBEAP is a middleware platform for Java 2 Platform, Enterprise Edition(J2EE) applications.This release of JBEAP for Red Hat Enterprise Linux 4 contains the JBossApplication Server and JBoss Seam. This release serves as a replacement toJBEAP 4.2.0.GA.The updated packages address the following security vulnerabilities: the JFreeChart component was vulnerable to multiple cross-site scripting (XSS) vulnerabilities. An attacker could misuse the image map feature toinject arbitrary web script or HTML via several attributes of the chartarea. (CVE-2007-6306) a vulnerability caused by exposing static java methods was located within the HSQLDB component. This could be utilized by an attacker to executearbitrary static java methods. (CVE-2007-4575) the setOrder method in the org.jboss.seam.framework.Query class did not properly validate user-supplied parameters. This vulnerability allowedremote attackers to inject and execute arbitrary EJBQL commands via theorder parameter. (CVE-2007-6433)All users are advised to upgrade to this release of JBEAP, which addressesthese vulnerabilities.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0158?
The severity of RHSA-2008:0158 is classified as moderate.
How do I fix RHSA-2008:0158?
To fix RHSA-2008:0158, you should update to the latest version of JBEAP provided by Red Hat.
What vulnerabilities does RHSA-2008:0158 address?
RHSA-2008:0158 addresses various flaws in the JBoss Application Server and JBoss Seam.
Is RHSA-2008:0158 applicable to my system?
RHSA-2008:0158 is applicable to systems running Red Hat Enterprise Linux 4 with JBEAP 4.2.0.GA.
Will applying the fix for RHSA-2008:0158 disrupt my applications?
Applying the fix for RHSA-2008:0158 may require application restarts, so timing the update is important.