JBoss Enterprise Application Platform 6.1.0 Update (RHSA-2013:0833)

high Nessus Plugin ID 66971

Synopsis

The remote Red Hat host is missing a security update.

Description

The version of JBoss Enterprise Application Platform 6.0.1 running on the remote system is vulnerable to the following issues:

- A man-in-the-middle attack is possible when applications running on JBoss Web use the COOKIE session tracking method. The flaw is in the org.apache.catalina.connector.Response.encodeURL() method. By making use of this, an attacker could obtain a user's jsessionid and hijack their session.
(CVE-2012-4529)

- If multiple applications used the same custom authorization module class name, a local attacker could deploy a malicious application authorization module that would permit or deny user access. (CVE-2012-4572)

- XML encryption backwards compatibility attacks could allow an attacker to force a server to use insecure legacy cryptosystems. (CVE-2012-5575)

- A NULL pointer dereference flaw could allow a malicious OCSP to crash applications performing OCSP verification.
(CVE-2013-0166)

- An OpenSSL leaks timing information issue exists that could allow a remote attacker to retrieve plaintext from the encrypted packets. (CVE-2013-0169)

- The JBoss Enterprise Application Platform administrator password and the sucker password are stored in a world- readable, auto-install XML file created by the GUI installer. (CVE-2013-0218)

- Tomcat incorrectly handles certain authentication requests. A remote attacker could use this flaw to inject a request that would get executed with a victim's credentials. (CVE-2013-2067)

Solution

Upgrade the installed JBoss Enterprise Application Platform 6.0.1 to 6.1.0 or later.

See Also

https://www.redhat.com/security/data/cve/CVE-2012-4529.html

https://www.redhat.com/security/data/cve/CVE-2012-4572.html

https://www.redhat.com/security/data/cve/CVE-2012-5575.html

https://www.redhat.com/security/data/cve/CVE-2013-0166.html

https://www.redhat.com/security/data/cve/CVE-2013-0169.html

https://www.redhat.com/security/data/cve/CVE-2013-0218.html

https://www.redhat.com/security/data/cve/CVE-2013-2067.html

http://www.nessus.org/u?c7770d98

Plugin Details

Severity: High

ID: 66971

File Name: redhat-RHSA-2013-0833.nasl

Version: 1.20

Type: local

Agent: unix

Published: 6/24/2013

Updated: 12/5/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Information

CPE: cpe:/a:redhat:jboss_enterprise_application_platform:6.0.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release

Exploit Ease: No known exploits are available

Patch Publication Date: 5/20/2013

Vulnerability Publication Date: 10/10/2012

Reference Information

CVE: CVE-2012-4529, CVE-2012-4572, CVE-2012-5575, CVE-2013-0166, CVE-2013-0169, CVE-2013-0218, CVE-2013-2067

BID: 57652, 57778, 59799, 60040, 60043, 60045, 60268

RHSA: 2013:0833