First published: Thu Jun 09 2016(Updated: )
Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.<br>Security Fix(es):<br><li> A denial of service flaw was found in the way Spring processes inline DTD declarations. A remote attacker could submit a specially crafted XML file that would cause out-of-memory errors when parsed. (CVE-2015-3192)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise BRMS Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2016:1219 is classified as moderate.
RHSA-2016:1219 addresses a denial of service flaw in the way Spring processes inline DTD declarations.
To fix RHSA-2016:1219, update to the latest patched version of Red Hat JBoss BRMS.
Users of Red Hat JBoss BRMS are affected by the vulnerabilities addressed in RHSA-2016:1219.
Yes, a remote attacker could exploit the vulnerability in RHSA-2016:1219 to initiate a denial of service attack.