Skip to main content

JBoss Multiple Products Remote Code Execution Vulnerability

Last Update Date: 27 Jun 2014 11:52 Release Date: 27 Jun 2014 3741 Views

RISK: Medium Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

A vulnerability was identified in Red Hat JBoss Web Framework Kit, Enterprise Application Platform and Enterprise Web Platform.
 

The vulnerability is caused due to an error related to Seam logging, which can be exploited to execute arbitrary code via specially crafted authentication headers.


Impact

  • Remote Code Execution

System / Technologies affected

  • Red Hat JBoss Web Framework Kit 2.5
  • Red Hat JBoss Enterprise Application Platform 5
  • Red Hat JBoss Enterprise Application Platform 5.2
  • Red Hat JBoss Web Platform 5
  • Red Hat JBoss Web Platform 5.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link