RHSA-2013:0569: Important: JBoss Web Services security update
JBoss Enterprise SOA Platform is the next-generation ESB and businessprocess automation infrastructure. JBoss Enterprise Portal Platform is theopen source implementation of the Java EE suite of services and Portalservices running atop JBoss Enterprise Application Platform.An attack technique was found against the W3C XML Encryption Standard whenblock ciphers were used in cipher-block chaining (CBC) mode. A remoteattacker could use this flaw to conduct chosen-ciphertext attacks, leadingto the recovery of the entire plain text of a particular cryptogram byexamining the differences between SOAP (Simple Object Access Protocol)responses sent from JBoss Web Services. (CVE-2011-1096)Red Hat would like to thank Juraj Somorovsky of Ruhr-University Bochum forreporting this issue.Note: Manual action is required to apply this update. The CVE-2011-1096issue is an attack on the WS-Security standard itself. Using newGalois/Counter Mode (GCM) based algorithms for WS-Security encryption isthe W3C suggested way of dealing with this issue. To use GCM algorithms inyour application, update the encrypt element of all jboss-ws-securityconfiguration to specify a GCM algorithm. The following is an exampledirective:encrypt type="x509v3" algorithm="aes-128-gcm" alias="wsse"Warning: Before applying this update, back up your JBoss installation,including any databases, database settings, applications, configurationfiles, and so on.All users of JBoss Enterprise SOA Platform 4.3 CP05 and JBoss EnterprisePortal Platform 4.3 CP07 as provided from the Red Hat Customer Portal areadvised to apply this update.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:0569?
The severity of RHSA-2013:0569 is classified as important according to Red Hat's security classification.
How do I fix RHSA-2013:0569?
To fix RHSA-2013:0569, update your JBoss Enterprise SOA Platform to the latest patched version provided by Red Hat.
What vulnerabilities does RHSA-2013:0569 address?
RHSA-2013:0569 addresses security vulnerabilities related to the JBoss Enterprise SOA Platform that could lead to unauthorized access or manipulation.
Is RHSA-2013:0569 applicable to my system?
RHSA-2013:0569 is applicable to systems running JBoss Enterprise SOA Platform versions affected by the vulnerabilities described in the advisory.
When was RHSA-2013:0569 released?
RHSA-2013:0569 was released on March 6, 2013.