RHSA-2013:0261: Important: JBoss Enterprise Application Platform 4.3.0 CP10 security update
JBoss Enterprise Application Platform is a platform for Java applications,which integrates the JBoss Application Server with JBoss Hibernate andJBoss Seam.An attack technique was found against the W3C XML Encryption Standard whenblock ciphers were used in cipher-block chaining (CBC) mode. A remoteattacker could use this flaw to conduct chosen-ciphertext attacks, leadingto the recovery of the entire plain text of a particular cryptogram byexamining the differences between SOAP (Simple Object Access Protocol)responses sent from JBoss Web Services. (CVE-2011-1096)Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochum forreporting this issue.Note: Manual action is required to apply this update. The CVE-2011-1096issue is an attack on the WS-Security standard itself. Using newGalois/Counter Mode (GCM) based algorithms for WS-Security encryption isthe W3C suggested way of dealing with this issue. To use GCM algorithms inyour application, update the encrypt element of all jboss-ws-securityconfiguration to specify a GCM algorithm. The following is an exampledirective:encrypt type="x509v3" algorithm="aes-128-gcm" alias="wsse"Warning: Before applying this update, back up your existing JBossEnterprise Application Platform installation (including all applicationsand configuration files).All users of JBoss Enterprise Application Platform 4.3.0 CP10 as providedfrom the Red Hat Customer Portal are advised to apply this update.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:0261?
RHSA-2013:0261 is classified as important due to its potential impact on Java applications.
How do I fix RHSA-2013:0261?
To resolve RHSA-2013:0261, update to the latest version of JBoss Enterprise Application Platform as recommended in the advisory.
What are the potential risks of RHSA-2013:0261?
The risks associated with RHSA-2013:0261 include possible exposure to attack techniques against the W3C XML Encryption Standard.
Who is affected by RHSA-2013:0261?
RHSA-2013:0261 affects users of the JBoss Enterprise Application Platform that utilize block ciphers in cipher-block encryption.
When was RHSA-2013:0261 released?
RHSA-2013:0261 was released on March 7, 2013.