copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2012.0335 - [RedHat] JBoss Enterprise BRMS Platform: Multiple vulnerabilities

Date: 03 April 2012
References: ESB-2011.1224  ESB-2012.0268  ESB-2012.0315  ESB-2012.0409  ESB-2012.0645  ESB-2012.0718  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2012.0335
           Moderate: JBoss Enterprise BRMS Platform 5.2.0 update
                               3 April 2012

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           JBoss Enterprise BRMS Platform
Publisher:         Red Hat
Operating System:  Red Hat
Impact/Access:     Access Privileged Data         -- Remote/Unauthenticated      
                   Provide Misleading Information -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2012-0818 CVE-2011-4314 

Reference:         ESB-2012.0315
                   ESB-2012.0268
                   ESB-2011.1224

Original Bulletin: 
   https://rhn.redhat.com/errata/RHSA-2012-0441.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: JBoss Enterprise BRMS Platform 5.2.0 update
Advisory ID:       RHSA-2012:0441-01
Product:           JBoss Enterprise Middleware
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2012-0441.html
Issue date:        2012-04-02
CVE Names:         CVE-2011-4314 CVE-2012-0818 
=====================================================================

1. Summary:

JBoss Enterprise BRMS Platform 5.2.0 roll up patch 1, which fixes two
security issues, various bugs, and adds enhancements, is now available from
the Red Hat Customer Portal.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

2. Description:

JBoss Enterprise BRMS Platform is a business rules management system for
the management, storage, creation, modification, and deployment of JBoss
Rules.

This roll up patch serves as a cumulative upgrade for JBoss Enterprise BRMS
Platform 5.2.0. It includes various bug fixes and enhancements. The
following security issues are also fixed with this release:

It was found that RESTEasy was vulnerable to XML External Entity (XXE)
attacks. If a remote attacker submitted a request containing an external
XML entity to a RESTEasy endpoint, the entity would be resolved, allowing
the attacker to read files accessible to the user running the application
server. This flaw affected DOM (Document Object Model) Document and JAXB
(Java Architecture for XML Binding) input. (CVE-2012-0818)

It was found that the Attribute Exchange (AX) extension of OpenID4Java was
not checking to ensure attributes were signed. If AX was being used to
receive information that an application only trusts the identity provider
to assert, a remote attacker could use this flaw to conduct
man-in-the-middle attacks and compromise the integrity of the information
via a specially-crafted request. By default, only the JBoss Seam openid
example application uses OpenID4Java. (CVE-2011-4314)

Warning: Before applying the update, back up your existing JBoss Enterprise
BRMS Platform installation (including its databases, applications,
configuration files, and so on).

All users of JBoss Enterprise BRMS Platform 5.2.0 as provided from the Red
Hat Customer Portal are advised to apply this roll up patch.

3. Solution:

The References section of this erratum contains a download link (you must
log in to download the update). Before applying the update, back up your
existing JBoss Enterprise BRMS Platform installation (including its
databases, applications, configuration files, and so on).

Note that it is recommended to halt the JBoss Enterprise BRMS Platform
server by stopping the JBoss Application Server process before installing
this update, and then after installing the update, restart the JBoss
Enterprise BRMS Platform server by starting the JBoss Application Server
process.

4. Bugs fixed (http://bugzilla.redhat.com/):

754386 - CVE-2011-4314 openid4java (AX extension): MITM due to improper validation of AX attribute signatures
785631 - CVE-2012-0818 RESTEasy: XML eXternal Entity (XXE) flaw
5. References:

https://www.redhat.com/security/data/cve/CVE-2011-4314.html
https://www.redhat.com/security/data/cve/CVE-2012-0818.html
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=brms&downloadType=securityPatches&version=5.2.0

6. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2012 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFPegiDXlSAg2UNWIIRAiHIAJ0dX1wySlAbuOQrdwiAGH87m4mujACgm4Mh
IlAcwcywyUek/P2a3yjd+5E=
=P/bu
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBT3pMAO4yVqjM2NGpAQLb1w//Q9xVPXyVH32kvPuEtNByfw2y91k2y9wS
9ejTDbIkD3uzpDTV+QFvwntoQN6gDHwptu74B0/aTElWXsddcwa7VJFMQQQte5ge
Ysd3fm0U94r9ADPbCRS4ySauo4eOPP4IZ/rupw7NuF0nra+MFQHH1vq65DyX8EMN
7SaF9qr+On7lfUSvQKhM6dQWJ5G+sYYe9mFZ9zYeE1v1PYzW78qJVo8yzL41PXqI
6UqEv9W7LotRjghsxA/FGt0OpNiwunj9ceCgEpddOjbQdJfJwz2Ina3CYXaCd6jL
x8wHexFlVcZpHmKqnB68wbLr7ZIxlzS5aM4baErWJZfS+k80SNipaNXQDGIbn9Me
iHQokz+F4icUrxcJDyjBArRr3xoXPenyH3YhJcDzz/xSResxupBT0kSgxOI3bmly
OsMHzRXJZJFMW8S0UI38vp12iUuCyk4x251Q6clRPTekzfo/Hh/YI5XjNqjTAdy7
5iJO6L2MnLqL2AarDcGXvMx+CKUiRiMMKeIHyVzTKVCd++FPOP5AYliRY5wFNJ8M
hHy94+AL2VsgR9fARD3OPKnK9TvIqoC96Jepn0jWwoNhy5ujxFDnA5PSGnOdoiNL
tkn1+5aC1ZaUovAd2SJr83TlPGlS31Y2bPrnN85t31McPXQ7gZfk95RygWGsuEOt
9lVC3r1iUgU=
=be/v
-----END PGP SIGNATURE-----