RHSA-2018:0296: Moderate: Red Hat JBoss Data Virtualization 6.4 security update

Published Feb 13, 2018
·
Updated

Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems - such as multiple databases, XML files, and even Hadoop systems - appear as a set of tables in a local database.<br>This release of Red Hat JBoss Data Virtualization 6.4 serves as a replacement for Red Hat JBoss Data Virtualization 6.3.8, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References.<br>Security Fix(es):<br><li> JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user. (CVE-2016-6343)</li> <li> It has been reported that CSRF tokens are not properly handled in JBoss BPM suite dashbuilder. Old tokens generated during an active session can be used to bypass CSRF protection. In addition, the tokens are sent in query string so they can be exposed through the browser's history, referrers, web logs, and other sources. Attackers may be able to obtain old tokens from various sources in the network and perform CSRF attacks successfully. (CVE-2016-7034)</li> These issues were discovered by Jeremy Choi (Red Hat Product Security Team).

Affected Software

1 affected component
Red Hat JBoss Data Virtualization

Remediation

Event History

Jun 21, 2024
Advisory Published
via Red Hat·06:01 AM
Data Sourced
via Red Hat·06:01 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2018:0296?

The severity of RHSA-2018:0296 is classified as important.

2

How do I fix RHSA-2018:0296?

To fix RHSA-2018:0296, apply the recommended updates to Red Hat JBoss Data Virtualization as described in the advisory.

3

What vulnerabilities are addressed in RHSA-2018:0296?

RHSA-2018:0296 addresses multiple vulnerabilities in Red Hat JBoss Data Virtualization that could lead to unauthorized access and potential data manipulation.

4

Who is affected by RHSA-2018:0296?

All users of Red Hat JBoss Data Virtualization versions prior to the fixed updates are affected by RHSA-2018:0296.

5

Is there a workaround for RHSA-2018:0296?

There are no recommended workarounds for RHSA-2018:0296, and updating is advised to mitigate the risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203