RHSA-2016:1428: Important: Red Hat JBoss BRMS 6.3.1 security and bug fix update
Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.Security Fix(es): A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter. (CVE-2016-4999) This issue was discovered by David Gutierrez (Red Hat).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1428?
The severity of RHSA-2016:1428 is classified as important due to its potential impact on data security.
How do I fix RHSA-2016:1428?
To fix RHSA-2016:1428, update your Red Hat JBoss BRMS to the latest available version that addresses the security flaw.
What products are affected by RHSA-2016:1428?
RHSA-2016:1428 affects Red Hat JBoss BRMS, specifically versions prior to the security update.
What type of vulnerability is identified in RHSA-2016:1428?
RHSA-2016:1428 identifies a SQL injection vulnerability in the Dashbuilder component of JBoss BRMS.
Is a workaround available for RHSA-2016:1428?
There are no official workarounds for RHSA-2016:1428; applying the security update is the recommended action.