Red Hat JBoss Web Framework Kit Information Leakage Vulnerability

Source: Internet
Author: User
Tags jboss

Release date:
Updated on:

Affected Systems:
RedHat JBoss Web Framework Kit 2.4.0
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-6447, CVE-2013-6448

Red Hat JBoss Web Framework Kit makes it easier to build and maintain light-rich Java applications using popular open-source technologies. It is included in the JBoss Enterprise Application Platform and can be separately provided for the JBoss Enterprise Web Server.

An error exists in the InterfaceGenerator handler of JBoss Seam Remoting in versions earlier than Red Hat JBoss Web Framework Kit 2.4.0, which can cause attackers to obtain all classes and methods in the class path; an error exists when parsing the ExecutionHandler, PollHandler, and SubscriptionHandler XML entities in JBoss Seam Remoting. Attackers can refer to the special XML documents containing external entities, attackers can exploit this vulnerability to obtain the content of certain files.

<* Source: Jon Passki

Link: http://secunia.com/advisories/56572/
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:

RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:


RHSA-2014: 0045-1:
Https://rhn.redhat.com/errata/RHSA-2014-0045.html

Red Hat:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1044794
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1044784

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.