First published: Thu Aug 14 2014(Updated: )
JBoss Enterprise Portal Platform is the open source implementation of the<br>Java EE suite of services and Portal services running atop JBoss Enterprise<br>Application Platform. It comprises a set of offerings for enterprise<br>customers who are looking for pre-configured profiles of JBoss Enterprise<br>Middleware components that have been tested and certified together to<br>provide an integrated experience.<br>It was found that XStream could deserialize arbitrary user-supplied XML<br>content, representing objects of any type. A remote attacker able to pass<br>XML to XStream could use this flaw to perform a variety of attacks,<br>including remote code execution in the context of the server running the<br>XStream application. (CVE-2013-7285)<br>It was found that the secure processing feature of Xalan-Java had<br>insufficient restrictions defined for certain properties and features.<br>A remote attacker able to provide Extensible Stylesheet Language<br>Transformations (XSLT) content to be processed by an application using<br>Xalan-Java could use this flaw to bypass the intended constraints of the<br>secure processing feature. Depending on the components available in the<br>classpath, this could lead to arbitrary remote code execution in the<br>context of the application server running the application that uses<br>Xalan-Java. (CVE-2014-0107)<br>All users of JBoss Enterprise Portal Platform 5.2.2 as provided from the<br>Red Hat Customer Portal are advised to install this update.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.