RHSA-2017:1255: Moderate: Red Hat JBoss Enterprise Application Platform security update
Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7.This release of Red Hat JBoss Enterprise Application Platform 6.4.15 serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.14, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.Security Fix(es): It was discovered that under certain conditions RESTEasy could be forced to parse a request with YamlProvider, resulting in unmarshalling of potentially untrusted data. An attacker could possibly use this flaw execute arbitrary code with the permissions of the application using RESTEasy. (CVE-2016-9606) Red Hat would like to thank Moritz Bechler (AgNO3 GmbH & Co. KG) for reporting these issues.
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:1255?
RHSA-2017:1255 is classified as a moderate severity issue.
How do I fix RHSA-2017:1255?
To address RHSA-2017:1255, you should upgrade to the latest version of Red Hat JBoss Enterprise Application Platform 6.
What software is affected by RHSA-2017:1255?
RHSA-2017:1255 affects Red Hat JBoss Enterprise Application Platform 6.4.14 and earlier versions.
What are the consequences of not addressing RHSA-2017:1255?
Failure to address RHSA-2017:1255 may expose your applications to potential vulnerabilities and security risks.
Is there a workaround for RHSA-2017:1255?
There are no specific workarounds identified for RHSA-2017:1255; upgrading is recommended.