Operating System:

[RedHat]

Published:

01 November 2019

Protect yourself against future threats.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.4052
              Red Hat Decision Manager 7.5.0 Security Update
                              1 November 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Red Hat Decision Manager 7.5.0
Publisher:         Red Hat
Operating System:  Red Hat
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Read-only Data Access           -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-14379 CVE-2019-12814 CVE-2019-12384

Reference:         ASB-2019.0303
                   ASB-2019.0299
                   ASB-2019.0287
                   ASB-2019.0284
                   ESB-2019.3978

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2019:3292

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: Red Hat Decision Manager 7.5.0 Security Update
Advisory ID:       RHSA-2019:3292-01
Product:           Red Hat Decision Manager
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:3292
Issue date:        2019-10-31
CVE Names:         CVE-2019-12384 CVE-2019-12814 CVE-2019-14379 
=====================================================================

1. Summary:

An update is now available for Red Hat Decision Manager.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Decision Manager is an open source decision management platform
that combines business rules management, complex event processing, Decision
Model & Notation (DMN) execution, and Business Optimizer for solving
planning problems. It automates business decisions and makes that logic
available to the entire business. 

This release of Red Hat Decision Manager 7.5.0 serves as an update to Red
Hat Decision Manager 7.4.1, and includes bug fixes and enhancements, which
are documented in the Release Notes document linked to in the References.

Security Fix(es):

* jackson-databind: default typing mishandling leading to remote code
execution (CVE-2019-14379)

* jackson-databind: failure to block the logback-core class from
polymorphic deserialization leading to remote code execution
(CVE-2019-12384)

* jackson-databind: polymorphic typing issue allows attacker to read
arbitrary local files on the server via crafted JSON message
(CVE-2019-12814)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

3. Solution:

For on-premise installations, before applying the update, back up your
existing installation, including all applications, configuration files,
databases and database settings, and so on.

It is recommended to halt the server by stopping the JBoss Application
Server process before installing this update; after installing the update,
restart the server by starting the JBoss Application Server process.

The References section of this erratum contains a download link (you must
log in to download the update).

4. Bugs fixed (https://bugzilla.redhat.com/):

1725795 - CVE-2019-12814 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message.
1725807 - CVE-2019-12384 jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution
1737517 - CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution

5. References:

https://access.redhat.com/security/cve/CVE-2019-12384
https://access.redhat.com/security/cve/CVE-2019-12814
https://access.redhat.com/security/cve/CVE-2019-14379
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=rhdm&version=7.5.0
https://access.redhat.com/documentation/en-us/red_hat_decision_manager/7.5/html/release_notes_for_red_hat_decision_manager_7.5/index

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXbsZw9zjgjWX9erEAQhkaRAAp17lf64uh17WahSuHyjs+tMdRmVyYY6b
pEmVg7eWgN9mktZOi/8avJ3t4lh9emFSzD+rD71KILqOndxr+A6Dr7lbaFlIWDmR
tZJMrUjtG9vw6OEWTcCs4qWJJ3C6Uhg9aGzAG6fygb8Bg6C/RevygGdEP05uZd0m
CUubKah6Q7DXX4tFwaTLGIP2zpWl9nOjvtYKK6BCrCcLvLutBTdBW9IDhWijUBmN
jVIIhHR3GbgddhMLYlJYpue/tQXR++7/9MgEtpTODaZlKo56jAx822ZBMrNtqi1y
u6YrM5goUvdXqa10+UnSqQqupRPZ+m4VCL3m1w7v7GHpR7dMcBAfKAtxne/Ew6jH
J7UdCQ9ssA+MwAPdjOGixJPyqq0XcB07RXNKY1S1278288l0IZpWl9Gj//DCqliV
CZnFmD9rRZb8mX25Igd3pr6H4bZHDea2oV8hSbc0jPlgEjqwr3YHEKy92snS67eE
iX/giwGShRfulaMn7cLWwmXHOxzXXa1CvyvD58bXV8JzMhux34auGzLPCtwaSzrY
i5kiG2p6b+WEPh1MmJrUO4YOHcH+gQTE/lCL0VEYqFazgiRxwOiOk8NbtjgWPLLN
P/6hGWJzOEdOUDA0oPOXIHQfNJCQDbTfUUhfSiNmd5QinrflxcTGm4DSuiqjePPE
pmThojMoEUM=
=K5gQ
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXbtvJGaOgq3Tt24GAQjkSBAAmPXw4Go8X/2Dc9Ny0abgMzTJWD0lM3Ly
0zcRo1sdUtVoUT3XYg9iq0mWOP445OFUOQRKR9EUrghU2tTBVeaIaFBWOmonf3/z
O7ZajQR83eV9GXnhr2uin9glGk4zqTXifS0mD8GEOkw8VcNYaDt1Dz0ZZqAB8p5q
csQpIkvwR6TJEwtJ3VtKFpOE3wKNF2iEH93koF2OcVr6kv4FmEzToV6X+c4tF9vU
vNGUFWq7+Z/OpS/4uQtE4VWiVqnOKv8gUSQ7LBjpPZPsxQnFlRbNrLjX2KLTTEWo
uwFvvmjSA4/poQnF5Rvg3ceIfI1mJDFmP27kwpiMOmlGiTVypVrPmWFCsiuiDST1
ZwX8OqxA4utTtX8tbqjumZfxr1dTP5W4MLAycUt7vSCjB7olowsyMmKRZngPEEiD
XXww13E9zBX4waAU692ybn9Ito+GqVCmuapbS7axHxhq/QRuMXbwoJcozA8c/ZGi
8s2lnPg1RQlqpWpebh097bZ7+qHwlRTkvw7YHzFPO1QHostMFWPwuY3Nr8QPyYHU
eSZoq8MLjRtXvYvrx1/vLJq3USbyjF2upzVM9J4kDSprHHfm8QeDx/ZCPzgcNXUD
vSPaVWiONrbrn6VAjRbpiDhX0otTjMI/fPRny9vWzWZZPbnu/l7cF0Vw+SDq6vEB
Oc+VHUF9CFc=
=mAku
-----END PGP SIGNATURE-----