RHSA-2013:0533: Important: JBoss Enterprise SOA Platform 5.3.1 update

Published Feb 20, 2013
·
Updated

Security:JBoss Web Services leaked side-channel data when distributing symmetrickeys (for XML encryption), allowing a remote attacker to recover the entireplain text form of a symmetric key. (CVE-2011-2487)Spring framework could possibly evaluate Expression Language (EL)expressions twice, allowing a remote attacker to execute arbitrary code inthe context of the application server, or to obtain sensitive informationfrom the server. (CVE-2011-2730)Note: Manual action is required to apply the fix for CVE-2011-2730. If yoursystem has deployed applications which use Spring framework, the contextparameter "springJspExpressionSupport" must be set to "false" to mitigatethis flaw, for example, in the application's web.xml file. This willprevent the double-evaluation of EL expressions that led to this flaw.An XSS flaw allowed a remote attacker to perform an XSS attack againstvictims using the JMX Console. (CVE-2011-4575)SecurityAssociation.getCredential() returned the previous credential ifno security context was provided. Depending on the deployed applications,this could possibly allow a remote attacker to hijack the credentials of apreviously-authenticated user. (CVE-2012-3370)A denial of service flaw was found in the implementation of associativearrays (hashes) in JRuby. An attacker able to supply a large number ofinputs to a JRuby application (such as HTTP POST request parameters sent toa web application) that are used as keys when inserting data into an arraycould trigger multiple hash function collisions, making array operationstake an excessive amount of CPU time. To mitigate this issue, the Murmurhash function has been replaced with the Perl hash function.(CVE-2012-5370)Note: JBoss Enterprise SOA Platform only provides JRuby as a dependency ofthe scriptingchain quickstart example application. The CVE-2012-5370 flawis not exposed unless the version of JRuby shipped with that quickstart isused by a deployed, custom application.Configuring the JMX Invoker to restrict access to users with specificroles did not actually restrict access, allowing remote attackers withvalid JMX Invoker credentials to perform JMX operations accessible toroles they are not a member of. (CVE-2012-5478)twiddle.sh accepted credentials as command line arguments, allowing localusers to view them via a process listing. (CVE-2009-5066)NonManagedConnectionFactory logged the username and password in plain textwhen an exception was thrown. This could lead to the exposure ofauthentication credentials if local users had permissions to read the logfile. (CVE-2012-0034)The JMXInvokerHAServlet and EJBInvokerHAServlet invoker servlets allowunauthenticated access by default in some profiles. The securityinterceptor's second layer of authentication prevented direct exploitationof this flaw. If the interceptor was misconfigured or inadvertentlydisabled, this flaw could lead to arbitrary code execution in the contextof the user running the JBoss server. (CVE-2012-0874)CallerIdentityLoginModule retained the password from the previous call if anull password was provided. In non-default configurations this couldpossibly lead to a remote attacker hijacking a previously-authenticateduser's session. (CVE-2012-3369)Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochumfor reporting CVE-2011-2487, and Tyler Krpata for reporting CVE-2011-4575.The CVE-2012-3370 and CVE-2012-3369 issues were discovered by Carlo de Wolfof Red Hat; CVE-2012-5478 was discovered by Derek Horton of Red Hat; and CVE-2012-0874 was discovered by David Jorm of the Red Hat Security ResponseTeam.Warning: Before applying the update, back up your existing JBoss EnterpriseSOA Platform installation (including its databases, applications,configuration files, and so on).All users of JBoss Enterprise SOA Platform 5.3.0 as provided from the RedHat Customer Portal are advised to upgrade to JBoss Enterprise SOA Platform5.3.1.

Affected Software

1 affected component
Red Hat JBoss Enterprise SOA Platform

Remediation

Event History

Feb 20, 2013
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2013:0533?

The severity of RHSA-2013:0533 is considered critical due to the potential for remote attackers to recover symmetric keys.

2

How do I fix RHSA-2013:0533?

To fix RHSA-2013:0533, it is recommended to apply the latest security updates provided by your software vendor.

3

What systems are affected by RHSA-2013:0533?

RHSA-2013:0533 affects JBoss Web Services deployments that utilize XML encryption.

4

What vulnerability is associated with RHSA-2013:0533?

RHSA-2013:0533 is associated with CVE-2011-2487, which involves key leakage through side-channel attacks.

5

Is there a workaround for RHSA-2013:0533?

There are no specific workarounds for RHSA-2013:0533; patching is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203