Skip to navigation

Security Advisory Moderate: JBoss Enterprise Application Platform 4.3.0CP04 update

Advisory: RHSA-2009:0349-5
Type: Security Advisory
Severity: Moderate
Issued on: 2009-03-06
Last updated on: 2009-03-06
Affected Products: JBoss Enterprise Application Platform 4.3.0 EL5
CVEs (cve.mitre.org): CVE-2009-0027

Details

Updated JBoss Enterprise Application Platform (JBoss EAP) 4.3 packages that
fix various issues are now available for Red Hat Enterprise Linux 5 as
JBEAP 4.3.0.CP04.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

JBoss Enterprise Application Platform (JBoss EAP) is the market-leading
platform for innovative and scalable Java applications. JBoss EAP
integrates the JBoss Application Server with JBoss Hibernate and JBoss Seam
into a complete, simple enterprise solution.

This release of JBoss EAP for Red Hat Enterprise Linux 5 serves as a
replacement for JBEAP 4.3.0.CP03.

These updated packages include bug fixes and enhancements which are
detailed in the release notes. The link to the release notes is available
in the References section of this errata.

The following security issue is also fixed with this release:

The request handler in JBossWS did not correctly verify the resource path
when serving WSDL files for custom web service endpoints. This allowed
remote attackers to read arbitrary XML files with the permissions of the
EAP process. (CVE-2009-0027)

Warning: before applying this update, please back up the JBoss EAP
"server/[configuration]/deploy/" directory, as well as any other customized
configuration files.

All users of JBoss EAP 4.3 on Red Hat Enterprise Linux 5 are advised to
upgrade to these updated packages, which resolve these issues.


Solution

Before applying this update, make sure that all previously-released errata
relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red
Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

JBoss Enterprise Application Platform 4.3.0 EL5

SRPMS:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: 62a3e4b56ecbca130b2b337837bea59d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.src.rpm
File outdated by:  RHSA-2009:1649
    MD5: bfbf4dde9886d260e0f5ff6b3173defa
jacorb-2.3.0-1jpp.ep1.7.1.el5.src.rpm
File outdated by:  RHSA-2010:0379
    MD5: f5c0ba66cfbf2fa7fce6928f3a4965a2
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 778b2d6547856a02ee39eb116cab6a8d
jboss-cache-1.4.1-6.SP11.1.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 7bc4c10b70c215e55571e0edb5bfd927
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.src.rpm     MD5: c94c1443bba17f851fce038c360f9a96
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 2916b87f8b61727e3c52e804d8a70250
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 0c8be089223becf596311cfdd411fa60
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: b0cd23e35578cea517e105508b287dc9
jboss-vfs-1.0.0-1.ep1.el5.src.rpm     MD5: 007d26f8759bb4bedc38d810b3568f70
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.src.rpm
File outdated by:  RHSA-2010:0938
    MD5: 2877aa6399c43075063fd611e94622b0
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 7c8a10ebcd06293394c72e8c942fb5fe
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 462d13ef6a096a6a604b172c46d74b58
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: bf7fb7cc9fc1c3e0f60b2b7843f5322d
jgroups-2.4.5-2.1.ep1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: d6e3ab09842000503654ef7f6473d48a
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.src.rpm
File outdated by:  RHBA-2011:1298
    MD5: 853bbb1a57a4c1c14f92319661370453
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.src.rpm     MD5: 7bc966348bfb75b7ab0c30ef7b549290
ws-commons-policy-1.0-2jpp.ep1.7.el5.src.rpm     MD5: 8ae426c519a21314e84adfba08e796af
ws-scout0-0.7-0.rc2.4.el5.src.rpm     MD5: ec19600169aafc4e9a7226b4e5d32cba
 
IA-32:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 6e5d2a90de6258666451fd8e159aa47b
glassfish-jaxb-javadoc-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: 249adffe061a6a900d7a3445bf79c93d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm
File outdated by:  RHSA-2010:0379
    MD5: 8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     MD5: 5b516f5c14cca4688c6f8a235ff1f33b
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: d4ac2c6161a5442e3c3c18d656c0fca3
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: af6fc0ea4225c099db82eefc3af25ff1
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: f36c02344ed114b3c19b04db86ce7892
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     MD5: 0cebf37c147165e0c1f8365476dcbe24
jbossas-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2013:0249
    MD5: 26c3e8630379fa19244c4f468d3e7a98
jbossas-4.3.0.GA_CP04-bin-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm     MD5: 4d9cc919ff9022a372cb50743a076d7b
jbossas-client-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2013:0249
    MD5: e93d076b04852d919b2e5fa957f04bfb
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 9fb64ad8cadbc61515a388f113c43911
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 640931a2153940eac7f67307032a3db6
jbossws-common-1.0.0-2.GA_CP03.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2011:1306
    MD5: 822323f88c3d47029ba7d286d57b95c3
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: aeb812cf329b3fe9b1728b40a45633f1
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a1079c47d8048cd512239f78708fbfe3
rh-eap-docs-examples-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 9126da466b64e946cd048459337c3cfb
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.i386.rpm     MD5: 9b30a571ea52caf40e7ed2c76921bfe8
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     MD5: 6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     MD5: 8c944bb5d2e25e69447a440888292d50
 
x86_64:
glassfish-jaxb-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 6e5d2a90de6258666451fd8e159aa47b
glassfish-jaxb-javadoc-2.1.4-1.6.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: 249adffe061a6a900d7a3445bf79c93d
glassfish-jsf-1.2_10-0jpp.ep1.5.ep5.el5.noarch.rpm
File outdated by:  RHSA-2009:1649
    MD5: dea5ac4d2fd6d7d871d45c9a73aee38b
hibernate3-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 87bcbe6a6b379370e759d53aa08f0829
hibernate3-javadoc-3.2.4-1.SP1_CP07.0jpp.ep1.14.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 055c09cad5c6c64287c1a1c40b22e47b
jacorb-2.3.0-1jpp.ep1.7.1.el5.noarch.rpm
File outdated by:  RHSA-2010:0379
    MD5: 8ebf14958bbaf2b8dbb280906e34f47f
jakarta-commons-logging-jboss-1.1-4.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: fbdc10023ce06173779978c15e158341
jboss-cache-1.4.1-6.SP11.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 5cc73177dcec37f424792dcd70bcb220
jboss-jaxr-1.2.0-SP2.0jpp.ep1.3.2.el5.noarch.rpm     MD5: 5b516f5c14cca4688c6f8a235ff1f33b
jboss-messaging-1.4.0-2.SP3_CP07.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: d4ac2c6161a5442e3c3c18d656c0fca3
jboss-remoting-2.2.2-3.SP11.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: f50323b132c1ad6c48864beda7664c64
jboss-seam-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: af6fc0ea4225c099db82eefc3af25ff1
jboss-seam-docs-1.2.1-3.JBPAPP_4_3_0_GA.ep1.10.el5.1.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: f36c02344ed114b3c19b04db86ce7892
jboss-vfs-1.0.0-1.ep1.el5.noarch.rpm     MD5: 0cebf37c147165e0c1f8365476dcbe24
jbossas-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2013:0249
    MD5: 26c3e8630379fa19244c4f468d3e7a98
jbossas-4.3.0.GA_CP04-bin-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm     MD5: 4d9cc919ff9022a372cb50743a076d7b
jbossas-client-4.3.0-3.GA_CP04.2.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2013:0249
    MD5: e93d076b04852d919b2e5fa957f04bfb
jbossts-4.2.3-1.SP5_CP04.1jpp.ep1.2.el5.noarch.rpm
File outdated by:  RHSA-2010:0938
    MD5: 7b079e33f782cfc912ca72db9ace452c
jbossweb-2.0.0-6.CP09.0jpp.ep1.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 9fb64ad8cadbc61515a388f113c43911
jbossws-2.0.1-3.SP2_CP05.3.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 640931a2153940eac7f67307032a3db6
jbossws-common-1.0.0-2.GA_CP03.1.ep1.el5.noarch.rpm
File outdated by:  RHSA-2011:1306
    MD5: 822323f88c3d47029ba7d286d57b95c3
jbossws-framework-2.0.1-1.GA_CP03.2.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: aeb812cf329b3fe9b1728b40a45633f1
jgroups-2.4.5-2.1.ep1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 8484c3afb2fac56539dd7f33551ec255
rh-eap-docs-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: a1079c47d8048cd512239f78708fbfe3
rh-eap-docs-examples-4.3.0-4.GA_CP04.ep1.3.1.el5.noarch.rpm
File outdated by:  RHBA-2011:1298
    MD5: 9126da466b64e946cd048459337c3cfb
tanukiwrapper-3.2.1-2jpp.ep1.2.el5.x86_64.rpm     MD5: 4c1f387890e2a2b0dd05e010bfe61099
ws-commons-policy-1.0-2jpp.ep1.7.el5.noarch.rpm     MD5: 6417df20c955e47c1d75b548f73de028
ws-scout0-0.7-0.rc2.4.el5.noarch.rpm     MD5: 8c944bb5d2e25e69447a440888292d50
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

475258 - Tracker bug for the EAP 4.3.0.cp04 release for RHEL-5.
479668 - CVE-2009-0027 JBoss EAP unprivileged local xml file access


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/