First published: Thu Jul 14 2016(Updated: )
Red Hat JBoss BRMS is a business rules management system for the management, storage, creation, modification, and deployment of JBoss Rules.<br>Security Fix(es):<br><li> A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter. (CVE-2016-4999)</li> This issue was discovered by David Gutierrez (Red Hat).
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Enterprise BRMS Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2016:1428 is classified as important due to its potential impact on data security.
To fix RHSA-2016:1428, update your Red Hat JBoss BRMS to the latest available version that addresses the security flaw.
RHSA-2016:1428 affects Red Hat JBoss BRMS, specifically versions prior to the security update.
RHSA-2016:1428 identifies a SQL injection vulnerability in the Dashbuilder component of JBoss BRMS.
There are no official workarounds for RHSA-2016:1428; applying the security update is the recommended action.