JBoss Multiple Products Remote Code Execution Vulnerability
Last Update Date:
27 Jun 2014 11:52
Release Date:
27 Jun 2014
3741
Views
RISK: Medium Risk
TYPE: Operating Systems - Application Platforms
A vulnerability was identified in Red Hat JBoss Web Framework Kit, Enterprise Application Platform and Enterprise Web Platform.
The vulnerability is caused due to an error related to Seam logging, which can be exploited to execute arbitrary code via specially crafted authentication headers.
Impact
- Remote Code Execution
System / Technologies affected
- Red Hat JBoss Web Framework Kit 2.5
- Red Hat JBoss Enterprise Application Platform 5
- Red Hat JBoss Enterprise Application Platform 5.2
- Red Hat JBoss Web Platform 5
- Red Hat JBoss Web Platform 5.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
Vulnerability Identifier
Source
Related Link
Share with