RHSA-2016:1218: Moderate: Red Hat JBoss BPM Suite security and bug fix update
Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes.Security Fix(es): A denial of service flaw was found in the way Spring processes inline DTD declarations. A remote attacker could submit a specially crafted XML file that would cause out-of-memory errors when parsed. (CVE-2015-3192)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1218?
The severity of RHSA-2016:1218 is classified as moderate.
How do I fix RHSA-2016:1218?
To fix RHSA-2016:1218, update your Red Hat JBoss BPM Suite to the latest patched version provided by Red Hat.
What type of vulnerability is associated with RHSA-2016:1218?
RHSA-2016:1218 addresses a denial of service vulnerability related to Spring frameworks within the JBoss BPM Suite.
Which software version does RHSA-2016:1218 affect?
RHSA-2016:1218 affects Red Hat JBoss BPM Suite versions prior to the latest security update.
Is there a workaround for RHSA-2016:1218?
There are no documented workarounds for RHSA-2016:1218; applying the security update is recommended.