Security Advisory Moderate: JBoss Enterprise Application Platform 4.2.0.CP03 security update

Advisory: RHSA-2008:0827-6
Type: Security Advisory
Severity: Moderate
Issued on: 2008-08-05
Last updated on: 2008-08-05
Affected Products: JBoss Enterprise Application Platform 4.2.0 EL5
OVAL: N/A
CVEs (cve.mitre.org): CVE-2008-1285
CVE-2008-3273

Details

Updated JBoss Enterprise Application Platform (JBoss EAP) packages that
resolve several security issues are now available for Red Hat Enterprise
Linux 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

JBoss EAP is a middleware platform for Java 2 Platform, Enterprise Edition
(J2EE) applications. JBoss Seam is a framework for building Java Internet
applications by integrating the use of Asynchronous JavaScript and XML
(AJAX), JavaServer Faces (JSF), Java Persistence (JPA), Enterprise Java
Beans (EJB 3.0) and Business Process Management (BPM) technologies.

This release of JBoss EAP for Red Hat Enterprise Linux 5 contains the JBoss
Application Server and JBoss Seam. This release serves as a replacement for
JBoss EAP 4.2.0.GA, and fixes the following security issues:

These updated JBoss Enterprise Application Platform (JBoss EAP) packages
resolve the following security issues:

The JavaServer Faces (JSF) component was vulnerable to multiple cross-site
scripting (XSS) vulnerabilities. An attacker could use these flaws to
inject arbitrary web script or HTML. (CVE-2008-1285)

Unauthenticated users were able to access the status servlet, which could
allow remote attackers to acquire details about deployed web contexts.
(CVE-2008-3273)

These updated packages include bug fixes and enhancements in addition to
the security fixes listed here. For the full list, refer to the JBoss EAP
4.2.0.CP03 release notes, linked to in the "References" section of this
advisory.

Warning: before applying this update, please back up the JBoss EAP
"server/<configuration>/deploy/" directory, as well as any customized
configuration files.

Users of JBoss Enterprise Application Platform (JBoss EAP) should upgrade
to these updated packages, which contain backported patches to correct
these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

JBoss Enterprise Application Platform 4.2.0 EL5

SRPMS:
asm-1.5.3-1jpp.ep1.2.el5.src.rpm     01ad09dacec276e6bcc5f3c6377de20e
cglib-2.1.3-2jpp.ep1.6.el5.src.rpm     77ecac60ab173b2c6ecf54047a993388
glassfish-jaf-1.1.0-0jpp.ep1.11.el5.1.src.rpm
File outdated by:  RHSA-2008:0834
    a52abf6b9237443c9da7cd7bb60f43ec
glassfish-javamail-1.4.0-0jpp.ep1.9.el5.src.rpm
File outdated by:  RHSA-2008:0834
    4e2ec32fd5f3badd6a8b49b9a3c8abe9
glassfish-jsf-1.2_08-0jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2009:0348
    fd4e5a4dea4d5438b21db1a7cbeb8d63
hibernate3-3.2.4-1.SP1_CP03.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    475729cf3acb012536589cacc336dbfb
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.3.el5.1.src.rpm
File outdated by:  RHSA-2009:1143
    4517b9e095093fe3df93eedb4480a40a
hibernate3-entitymanager-3.2.1-1jpp.ep1.7.el5.src.rpm
File outdated by:  RHSA-2009:1143
    8c43069f1ceb28f926b06bfaf5bf3007
jboss-cache-1.4.1-4.SP9.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    411eb8aea1a884415876321e5d8263c2
jboss-remoting-2.2.2-3.SP7.0jpp.ep1.3.el5.src.rpm
File outdated by:  RHSA-2009:1143
    a332de1b929de6b4a06fb12707968c54
jboss-seam-1.2.1-1.ep1.6.el5.src.rpm
File outdated by:  RHSA-2009:1143
    f0fed5eff2c3cca5a32e95909cc5eacd
jbossas-4.2.0-4.GA_CP03.ep1.8.el5.1.src.rpm
File outdated by:  RHSA-2009:1143
    6c6ab1e6b065be8abcc17862375499ee
jbossts-4.2.3-1.SP5_CP01.1jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    de0378f8f437eff2fefa54bcb56a7429
jbossws-jboss42-1.2.1-0jpp.ep1.4.el5.1.src.rpm
File outdated by:  RHSA-2009:0348
    cab0e97546c8b93152f20cc7458a9ce9
jcommon-1.0.12-1jpp.ep1.3.el5.src.rpm     b90e5ed85726914466bb94c597761a54
jfreechart-1.0.9-1jpp.ep1.3.el5.1.src.rpm     44eb3a939a14d805a58ee3020c6dc450
jgroups-2.4.2-1.GA_CP01.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHSA-2009:1143
    45e1b2578c2273ed9edda53ac50c2be4
rh-eap-docs-4.2.0-3.GA_CP03.ep1.5.el5.src.rpm
File outdated by:  RHSA-2009:1143
    acfe4b9b92a078191b34e56feb321769
 
IA-32:
asm-1.5.3-1jpp.ep1.2.el5.noarch.rpm     d787c43e4bce216b275f8c71ab891961
cglib-2.1.3-2jpp.ep1.6.el5.noarch.rpm     403c91c1047e222c1cb16f36da017e9a
glassfish-jaf-1.1.0-0jpp.ep1.11.el5.1.noarch.rpm
File outdated by:  RHSA-2008:0834
    743733c669f6efda6e9426d16627f676
glassfish-javamail-1.4.0-0jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2008:0834
    ae6038fffe54a0c276279db9781f3f2c
glassfish-jsf-1.2_08-0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:0348
    c37cb2a4430a682d0e0f191586303c91
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.3.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    d0191f66c956b18f25518315dca72f97
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.3.el5.1.noarch.r
File outdated by:  RHSA-2009:1143
    58f4fb76f60ef0b02bd7825caa64bf73
hibernate3-entitymanager-3.2.1-1jpp.ep1.7.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    7a0a47e75345fe4306a5bfc7f82d1179
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.7.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fbd1128319fbe54a1d7d71f27456e0af
hibernate3-javadoc-3.2.4-1.SP1_CP03.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    10e4eeecf50844b2a02378382f22ffbc
jboss-cache-1.4.1-4.SP9.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5a4143ea9360ba9955d813b0dc28406e
jboss-remoting-2.2.2-3.SP7.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    50d17afc31b9cc3c383cc10c25c606c7
jboss-seam-1.2.1-1.ep1.6.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    15ed670f4216f12eb0609b8865fa8e96
jboss-seam-docs-1.2.1-1.ep1.6.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    c9f869d0b568c935b4f2e7a31af78e54
jbossas-4.2.0-4.GA_CP03.ep1.8.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    03263a0a138e219b1686b958cbddfdf3
jbossts-4.2.3-1.SP5_CP01.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fa271bee571393b7515f4dbc12f56beb
jbossws-jboss42-1.2.1-0jpp.ep1.4.el5.1.noarch.rpm
File outdated by:  RHSA-2009:0348
    2299646fbb9e6fc9f9e23abedc44e739
jcommon-1.0.12-1jpp.ep1.3.el5.noarch.rpm     dec511ca8b55cf97dfec1043afbbdf46
jfreechart-1.0.9-1jpp.ep1.3.el5.1.noarch.rpm     e3019ba8e1922bba8f6f087a71a0cf8e
jgroups-2.4.2-1.GA_CP01.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    b40ec6ffcfc43924e0c3dfba20f3dd59
rh-eap-docs-4.2.0-3.GA_CP03.ep1.5.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    3544dd5fce50c4b610a1f7200341318c
rh-eap-docs-examples-4.2.0-3.GA_CP03.ep1.5.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    9cd15a0291fba36d3e6e6ad5595266a8
 
x86_64:
asm-1.5.3-1jpp.ep1.2.el5.noarch.rpm     d787c43e4bce216b275f8c71ab891961
cglib-2.1.3-2jpp.ep1.6.el5.noarch.rpm     403c91c1047e222c1cb16f36da017e9a
glassfish-jaf-1.1.0-0jpp.ep1.11.el5.1.noarch.rpm
File outdated by:  RHSA-2008:0834
    743733c669f6efda6e9426d16627f676
glassfish-javamail-1.4.0-0jpp.ep1.9.el5.noarch.rpm
File outdated by:  RHSA-2008:0834
    ae6038fffe54a0c276279db9781f3f2c
glassfish-jsf-1.2_08-0jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2009:0348
    c37cb2a4430a682d0e0f191586303c91
hibernate3-annotations-3.2.1-1.patch02.1jpp.ep1.3.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    d0191f66c956b18f25518315dca72f97
hibernate3-annotations-javadoc-3.2.1-1.patch02.1jpp.ep1.3.el5.1.noarch.r
File outdated by:  RHSA-2009:1143
    58f4fb76f60ef0b02bd7825caa64bf73
hibernate3-entitymanager-3.2.1-1jpp.ep1.7.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    7a0a47e75345fe4306a5bfc7f82d1179
hibernate3-entitymanager-javadoc-3.2.1-1jpp.ep1.7.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fbd1128319fbe54a1d7d71f27456e0af
hibernate3-javadoc-3.2.4-1.SP1_CP03.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    10e4eeecf50844b2a02378382f22ffbc
jboss-cache-1.4.1-4.SP9.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    5a4143ea9360ba9955d813b0dc28406e
jboss-remoting-2.2.2-3.SP7.0jpp.ep1.3.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    50d17afc31b9cc3c383cc10c25c606c7
jboss-seam-1.2.1-1.ep1.6.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    15ed670f4216f12eb0609b8865fa8e96
jboss-seam-docs-1.2.1-1.ep1.6.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    c9f869d0b568c935b4f2e7a31af78e54
jbossas-4.2.0-4.GA_CP03.ep1.8.el5.1.noarch.rpm
File outdated by:  RHSA-2009:1143
    03263a0a138e219b1686b958cbddfdf3
jbossts-4.2.3-1.SP5_CP01.1jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    fa271bee571393b7515f4dbc12f56beb
jbossws-jboss42-1.2.1-0jpp.ep1.4.el5.1.noarch.rpm
File outdated by:  RHSA-2009:0348
    2299646fbb9e6fc9f9e23abedc44e739
jcommon-1.0.12-1jpp.ep1.3.el5.noarch.rpm     dec511ca8b55cf97dfec1043afbbdf46
jfreechart-1.0.9-1jpp.ep1.3.el5.1.noarch.rpm     e3019ba8e1922bba8f6f087a71a0cf8e
jgroups-2.4.2-1.GA_CP01.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    b40ec6ffcfc43924e0c3dfba20f3dd59
rh-eap-docs-4.2.0-3.GA_CP03.ep1.5.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    3544dd5fce50c4b610a1f7200341318c
rh-eap-docs-examples-4.2.0-3.GA_CP03.ep1.5.el5.noarch.rpm
File outdated by:  RHSA-2009:1143
    9cd15a0291fba36d3e6e6ad5595266a8
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

437082 - CVE-2008-1285 Cross-site scripting (XSS) vulnerability in Sun Java Server Faces
457757 - CVE-2008-3273 JBossEAP status servlet info leak


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/