First published: Wed May 14 2014(Updated: )
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint,<br>flexible, open source enterprise service bus and integration platform.<br>It was found that the Struts 1 ActionForm object allowed access to the<br>'class' parameter, which is directly mapped to the getClass() method.<br>A remote attacker could use this flaw to manipulate the ClassLoader used by<br>an application server running Struts 1. This could lead to remote code<br>execution under certain conditions. (CVE-2014-0114)<br>Refer to the readme.txt file included with the patch files for<br>installation instructions.<br>All users of Red Hat JBoss Fuse 6.1.0 as provided from the Red Hat Customer<br>Portal are advised to apply this security update.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.