RHSA-2018:1609: Important: Red Hat JBoss Enterprise Application Platform security update
Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server.Security Fix(es): jboss: jbossas: unsafe chown of server.log in jboss init script allows privilege escalation (CVE-2016-8656) jboss: jbossas writable config files allow privilege escalation (CVE-2016-8657) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:1609?
The severity of RHSA-2018:1609 is classified as important.
How do I fix RHSA-2018:1609?
To fix RHSA-2018:1609, upgrade to the remedial versions of the affected packages, specifically 5.2.0-23.ep5.el6 or 5.2.0-23.ep5.el5.
Which versions of Red Hat JBoss are affected by RHSA-2018:1609?
Red Hat JBoss versions prior to 5.2.0-23.ep5.el6 and 5.2.0-23.ep5.el5 are affected by RHSA-2018:1609.
What vulnerabilities are addressed in RHSA-2018:1609?
RHSA-2018:1609 addresses the unsafe chown of server.log in the jboss init script, allowing privilege escalation (CVE-2016-8656).
Is there a workaround for RHSA-2018:1609?
The recommended approach for RHSA-2018:1609 is to apply the available updates instead of relying on workarounds.