First published: Tue Mar 31 2015(Updated: )
Red Hat JBoss Data Virtualization is a lean data integration solution that<br>provides easy, real-time, and unified data access across disparate sources<br>to multiple applications and users. JBoss Data Virtualization makes data<br>spread across physically distinct systems-such as multiple databases, XML<br>files, and even Hadoop systems-appear as a set of tables in a local<br>database.<br>This roll up patch serves as a cumulative upgrade for Red Hat JBoss Data<br>Virtualization 6.0.0. It includes various bug fixes, which are listed in<br>the README file included with the patch files.<br>The following security issues are also fixed with this release,<br>descriptions of which can be found on the respective CVE pages linked in<br>the References section.<br>CVE-2012-6153 Apache HttpComponents client: SSL hostname verification<br>bypass, incomplete CVE-2012-5783 fix<br>CVE-2014-3577 Apache HttpComponents client: SSL hostname verification<br>bypass, incomplete CVE-2012-6153 fix<br>CVE-2014-3530 PicketLink: XXE via insecure DocumentBuilderFactory usage<br>CVE-2013-4002 Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP,<br>8017298)<br>CVE-2013-5855 Mojarra JSF: XSS due to insufficient escaping of<br>user-supplied content in outputText tags and EL expressions<br>CVE-2014-0075 Tomcat/JBossWeb: Limited DoS in chunked transfer encoding<br>input filter<br>CVE-2014-0099 Tomcat/JBossWeb: Request smuggling via malicious content<br>length header<br>CVE-2014-3481 JBoss AS JAX-RS: Information disclosure via XML eXternal<br>Entity (XXE)<br>CVE-2014-3490 RESTEasy: XXE via parameter entities<br>CVE-2014-0096 Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs<br>CVE-2014-0119 Tomcat/JBossWeb: XML parser hijack by malicious web<br>application<br>CVE-2014-0193 netty: DoS via memory exhaustion during data aggregation<br>CVE-2014-0227 Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter <br>Red Hat would like to thank James Roper of Typesafe for reporting<br>CVE-2014-0193, and Alexander Papadakis for reporting CVE-2014-3530.<br>The CVE-2012-6153 issue was discovered by Florian Weimer of Red Hat Product<br>Security, the CVE-2014-0075 and CVE-2014-3490 issues were discovered by<br>David Jorm of Red Hat Product Security, and the CVE-2014-3481 issue was<br>discovered by the Red Hat JBoss Enterprise Application Platform QE team.<br>All users of Red Hat JBoss Data Virtualization 6.0.0 as provided from the<br>Red Hat Customer Portal are advised to apply this roll up patch.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.