First published: Mon Nov 10 2014(Updated: )
Red Hat JBoss Enterprise Web Platform is a platform for Java applications,<br>which integrates the JBoss Web Server with JBoss Hibernate and JBoss Seam.<br>It was discovered that the HttpClient incorrectly extracted host name from<br>an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle<br>attacker could use this flaw to spoof an SSL server using a specially<br>crafted X.509 certificate. (CVE-2012-6153, CVE-2014-3577)<br>The CVE-2012-6153 issue was discovered by Florian Weimer of Red Hat<br>Product Security.<br>For additional information on these flaws, refer to the Knowledgebase<br>article in the References section.<br>All users of Red Hat JBoss Enterprise Web Platform 5.2.0 on Red Hat<br>Enterprise Linux 4, 5, and 6 are advised to upgrade to these updated<br>packages. The JBoss server process must be restarted for the update to<br>take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/apache-cxf | <2.2.12-14.patch_09.el6 | 2.2.12-14.patch_09.el6 |
redhat/apache-cxf | <2.2.12-14.patch_09.el6 | 2.2.12-14.patch_09.el6 |
redhat/apache-cxf | <2.2.12-14.patch_09.ep5.el5 | 2.2.12-14.patch_09.ep5.el5 |
redhat/apache-cxf | <2.2.12-14.patch_09.ep5.el5 | 2.2.12-14.patch_09.ep5.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.