Release date:
Updated on:
Affected Systems:
RedHat JBoss Web Framework Kit 2.4.0
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-6447, CVE-2013-6448
Red Hat JBoss Web Framework Kit makes it easier to build and maintain light-rich Java applications using popular open-source technologies. It is included in the JBoss Enterprise Application Platform and can be separately provided for the JBoss Enterprise Web Server.
An error exists in the InterfaceGenerator handler of JBoss Seam Remoting in versions earlier than Red Hat JBoss Web Framework Kit 2.4.0, which can cause attackers to obtain all classes and methods in the class path; an error exists when parsing the ExecutionHandler, PollHandler, and SubscriptionHandler XML entities in JBoss Seam Remoting. Attackers can refer to the special XML documents containing external entities, attackers can exploit this vulnerability to obtain the content of certain files.
<* Source: Jon Passki
Link: http://secunia.com/advisories/56572/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
RHSA-2014: 0045-1:
Https://rhn.redhat.com/errata/RHSA-2014-0045.html
Red Hat:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1044794
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1044784