RHSA-2013:0533: Important: JBoss Enterprise SOA Platform 5.3.1 update
Security:JBoss Web Services leaked side-channel data when distributing symmetrickeys (for XML encryption), allowing a remote attacker to recover the entireplain text form of a symmetric key. (CVE-2011-2487)Spring framework could possibly evaluate Expression Language (EL)expressions twice, allowing a remote attacker to execute arbitrary code inthe context of the application server, or to obtain sensitive informationfrom the server. (CVE-2011-2730)Note: Manual action is required to apply the fix for CVE-2011-2730. If yoursystem has deployed applications which use Spring framework, the contextparameter "springJspExpressionSupport" must be set to "false" to mitigatethis flaw, for example, in the application's web.xml file. This willprevent the double-evaluation of EL expressions that led to this flaw.An XSS flaw allowed a remote attacker to perform an XSS attack againstvictims using the JMX Console. (CVE-2011-4575)SecurityAssociation.getCredential() returned the previous credential ifno security context was provided. Depending on the deployed applications,this could possibly allow a remote attacker to hijack the credentials of apreviously-authenticated user. (CVE-2012-3370)A denial of service flaw was found in the implementation of associativearrays (hashes) in JRuby. An attacker able to supply a large number ofinputs to a JRuby application (such as HTTP POST request parameters sent toa web application) that are used as keys when inserting data into an arraycould trigger multiple hash function collisions, making array operationstake an excessive amount of CPU time. To mitigate this issue, the Murmurhash function has been replaced with the Perl hash function.(CVE-2012-5370)Note: JBoss Enterprise SOA Platform only provides JRuby as a dependency ofthe scriptingchain quickstart example application. The CVE-2012-5370 flawis not exposed unless the version of JRuby shipped with that quickstart isused by a deployed, custom application.Configuring the JMX Invoker to restrict access to users with specificroles did not actually restrict access, allowing remote attackers withvalid JMX Invoker credentials to perform JMX operations accessible toroles they are not a member of. (CVE-2012-5478)twiddle.sh accepted credentials as command line arguments, allowing localusers to view them via a process listing. (CVE-2009-5066)NonManagedConnectionFactory logged the username and password in plain textwhen an exception was thrown. This could lead to the exposure ofauthentication credentials if local users had permissions to read the logfile. (CVE-2012-0034)The JMXInvokerHAServlet and EJBInvokerHAServlet invoker servlets allowunauthenticated access by default in some profiles. The securityinterceptor's second layer of authentication prevented direct exploitationof this flaw. If the interceptor was misconfigured or inadvertentlydisabled, this flaw could lead to arbitrary code execution in the contextof the user running the JBoss server. (CVE-2012-0874)CallerIdentityLoginModule retained the password from the previous call if anull password was provided. In non-default configurations this couldpossibly lead to a remote attacker hijacking a previously-authenticateduser's session. (CVE-2012-3369)Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochumfor reporting CVE-2011-2487, and Tyler Krpata for reporting CVE-2011-4575.The CVE-2012-3370 and CVE-2012-3369 issues were discovered by Carlo de Wolfof Red Hat; CVE-2012-5478 was discovered by Derek Horton of Red Hat; and CVE-2012-0874 was discovered by David Jorm of the Red Hat Security ResponseTeam.Warning: Before applying the update, back up your existing JBoss EnterpriseSOA Platform installation (including its databases, applications,configuration files, and so on).All users of JBoss Enterprise SOA Platform 5.3.0 as provided from the RedHat Customer Portal are advised to upgrade to JBoss Enterprise SOA Platform5.3.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:0533?
The severity of RHSA-2013:0533 is considered critical due to the potential for remote attackers to recover symmetric keys.
How do I fix RHSA-2013:0533?
To fix RHSA-2013:0533, it is recommended to apply the latest security updates provided by your software vendor.
What systems are affected by RHSA-2013:0533?
RHSA-2013:0533 affects JBoss Web Services deployments that utilize XML encryption.
What vulnerability is associated with RHSA-2013:0533?
RHSA-2013:0533 is associated with CVE-2011-2487, which involves key leakage through side-channel attacks.
Is there a workaround for RHSA-2013:0533?
There are no specific workarounds for RHSA-2013:0533; patching is the recommended solution.