Red Hat update for JBoss Enterprise Web Server

by Carol~ Moderator - 5/8/12 7:36 AM

In Reply to: VULNERABILITIES / FIXES - May 08, 2012 by Carol~ Moderator

Release Date : 2012-05-08

Criticality level : Moderately critical
Impact : Security Bypass
Manipulation of data
Exposure of sensitive information
Privilege escalation
DoS
Where : From remote
Solution Status : Vendor Patch

Software: JBoss Enterprise Web Server 1.x
JBoss Enterprise Web Server EL5
JBoss Enterprise Web Server EL6

Description:
Red Hat has issued an update for JBoss Enterprise Web Server. This fixes two weaknesses and multiple vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions and gain escalated privileges and by malicious people to disclose potentially sensitive information, bypass certain security restrictions, and cause a DoS (Denial of Service).

Solution:
Updated packages are available via the Red Hat Customer Portal.

Original Advisory:
RHSA-2012:0542-01:
https://rhn.redhat.com/errata/RHSA-2012-0542.html

RHSA-2012:0543-01:
https://rhn.redhat.com/errata/RHSA-2012-0543.html

http://secunia.com/advisories/49080/