RHSA-2016:1429: Important: Red Hat JBoss BPM Suite 6.3.1 security and bug fix update
Red Hat JBoss BPM Suite is a business rules and processes management system for the management, storage, creation, modification, and deployment of JBoss rules and BPMN2-compliant business processes.Security Fix(es): A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter. (CVE-2016-4999) This issue was discovered by David Gutierrez (Red Hat).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:1429?
The severity of RHSA-2016:1429 is classified as important.
How do I fix RHSA-2016:1429?
To fix RHSA-2016:1429, apply the provided security patches to your Red Hat JBoss BPM Suite installation.
What specific issue does RHSA-2016:1429 address?
RHSA-2016:1429 addresses a security flaw in the way Dashbuilder performs certain operations.
Who is affected by RHSA-2016:1429?
RHSA-2016:1429 affects users of Red Hat JBoss BPM Suite.
Is there a known exploit for RHSA-2016:1429?
As of this advisory, there are no publicly known exploits specifically targeting RHSA-2016:1429.