RHEL 6Red Hat JBoss Enterprise Application Platform 7.1.0 (RHSA-2017:3454)

critical Nessus Plugin ID 105268

概要

遠端 Red Hat 主機缺少一個或多個適用於 Red Hat JBoss Enterprise Application Platform 7.1.0 的安全性更新。

說明

遠端 Redhat Enterprise Linux 6 主機上安裝的套件受到 RHSA-2017:3454 公告中提及的多個弱點影響。

Red Hat JBoss Enterprise Application Platform 是一個以 JBoss Application Server 為基礎,並提供給 Java 應用程式使用的平台。

此 Red Hat JBoss Enterprise Application Platform 7.1.0 版本是 Red Hat JBoss Enterprise Application Platform 7.0.0 的替代版本,其中包含數個錯誤修正和增強功能,詳情請參閱〈參照〉中的「版本資訊」連結。

安全性修正:

* 將長要求傳送至 EAP 7 時可造成拒絕服務。(CVE-2016-7046)

* jboss init 指令碼不安全的檔案處理方式導致本機權限提升。 (CVE-2016-8656)

* 透過 ObjectMapper 的 readValue 方法造成的還原序列化弱點可允許任意程式碼執行。 (CVE-2017-7525)

* JMSObjectMessage 將可能的惡意物件還原序列化,允許了遠端程式碼執行。
(CVE-2016-4978)

* Undertow 容易遭到任意 HTTP 標頭插入,以及回應分割。
(CVE-2016-4993)

* 網域控制站將不會將其管理 RBAC 組態散佈至某些從屬進而導致其權限提升。 (CVE-2016-5406)

* 若未設定要求標頭 Host 欄位內部 IP 位址會在重新導向上洩漏。 (CVE-2016-6311)

* 可能透過對伺服器記錄檔的 GET 要求發動 EAP 資源耗盡 DOS 攻擊。 (CVE-2016-8627)

* 低效的標頭快取可造成拒絕服務。 (CVE-2016-9589)

* 記錄檔檢視器允許經驗證的使用者透過路徑遊走讀取任意檔案。 (CVE-2017-2595)

* HTTP 要求走私弱點,這是因為在 HTTP 要求中允許無效字元所致。
(CVE-2017-2666)

* Websocket 不干淨的關閉可造成 IO 執行緒在迴圈中停滯。 (CVE-2017-2670)

* 將安全管理員的反射權限授予 Hibernate Validator 時,會發生特權提升問題。
(CVE-2017-7536)

* Undertow 剖析具有異常空格的 http 標頭時,可能發生 http 要求走私問題。
(CVE-2017-7559)

* 管理和應用程式領域的屬性型檔案為全域可讀取允許存取登入至系統的所有使用者的使用者和角色資訊。 (CVE-2017-12167)

* RBAC 組態允許具有 Monitor 角色的使用者檢視敏感資訊。 (CVE-2016-7061)

* 不正確的空格剖析會導致可能的 HTTP 要求走私問題。 (CVE-2017-12165)

Red Hat 感謝 Liao Xinxi (NSFOCUS) 報告 CVE-2017-7525;感謝 Calum Hutton (NCC Group) 和 Mikhail Egorov (Odin) 報告 CVE-2016-4993;感謝 Luca Bueti 報告 CVE-2016-6311;感謝 Gabriel Lavoie (Halogen Software) 報告 CVE-2016-9589;及感謝 Gregory Ramsperger 和 Ryan Moak 報告 CVE-2017-2670。CVE-2016-5406 問題是由 Tomaz Cerar (Red Hat) 所發現;CVE-2016-8627 問題是由 Darran Lofthouse (Red Hat) 和 Brian Stansberry (Red Hat) 所發現;CVE-2017-2666 問題是由 Radim Hatlapatka (Red Hat) 所發現;CVE-2017-7536 問題是由 Gunnar Morling (Red Hat) 所發現;CVE-2017-7559 和 CVE-2017-12165 問題是由 Stuart Douglas (Red Hat) 所發現;以及 CVE-2017-12167 問題是由 Brian Stansberry (Red Hat) 和 Jeremy Choi (Red Hat) 所發現。上游確認 WildFly 是 CVE-2016-6311 的原始報告者。

Tenable 已直接從 Red Hat Enterprise Linux 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 RHSA-2017:3454 中的指引更新 RHEL Red Hat JBoss Enterprise Application Platform 7.1.0 套件。

另請參閱

http://www.nessus.org/u?d4567d80

http://www.nessus.org/u?e41b214b

https://access.redhat.com/errata/RHSA-2017:3454

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=1344321

https://bugzilla.redhat.com/show_bug.cgi?id=1359014

https://bugzilla.redhat.com/show_bug.cgi?id=1362735

https://bugzilla.redhat.com/show_bug.cgi?id=1376646

https://bugzilla.redhat.com/show_bug.cgi?id=1379207

https://bugzilla.redhat.com/show_bug.cgi?id=1380852

https://bugzilla.redhat.com/show_bug.cgi?id=1388240

https://bugzilla.redhat.com/show_bug.cgi?id=1400344

https://bugzilla.redhat.com/show_bug.cgi?id=1404782

https://bugzilla.redhat.com/show_bug.cgi?id=1413028

https://bugzilla.redhat.com/show_bug.cgi?id=1436163

https://bugzilla.redhat.com/show_bug.cgi?id=1438885

https://bugzilla.redhat.com/show_bug.cgi?id=1462702

https://bugzilla.redhat.com/show_bug.cgi?id=1465573

https://bugzilla.redhat.com/show_bug.cgi?id=1481665

https://bugzilla.redhat.com/show_bug.cgi?id=1490301

https://bugzilla.redhat.com/show_bug.cgi?id=1491612

https://issues.redhat.com/browse/JBEAP-5322

Plugin 詳細資訊

嚴重性: Critical

ID: 105268

檔案名稱: redhat-RHSA-2017-3454.nasl

版本: 3.12

類型: local

代理程式: unix

已發布: 2017/12/15

已更新: 2025/4/29

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.7

Vendor

Vendor Severity: Important

CVSS v2

風險因素: High

基本分數: 7.5

時間性分數: 5.9

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2017-7525

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 8.8

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: p-cpe:/a:redhat:enterprise_linux:eap7-jboss-seam-int, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly8.2-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-vfs, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-aesh, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jettison-provider, p-cpe:/a:redhat:enterprise_linux:eap7-commons-logging-jboss-logmanager, p-cpe:/a:redhat:enterprise_linux:eap7-jbossws-spi, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap7-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-openssl, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jacc-api_1.5_spec, cpe:/o:redhat:enterprise_linux:6, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-restat-api, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-common, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-el, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jaspi-api_1.1_spec, p-cpe:/a:redhat:enterprise_linux:eap7-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap7-apache-commons-beanutils, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-client, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata-ejb, p-cpe:/a:redhat:enterprise_linux:eap7-shibboleth-java-support, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly10.1-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-cxf-xjc-dv, p-cpe:/a:redhat:enterprise_linux:eap7-jbossws-jaxws-undertow-httpspi, p-cpe:/a:redhat:enterprise_linux:eap7-jgroups, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-restat-bridge, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap6.4-to-eap7.0, p-cpe:/a:redhat:enterprise_linux:eap7-jcl-over-slf4j, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-saaj-api_1.3_spec, p-cpe:/a:redhat:enterprise_linux:eap7-mustache-java-compiler, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-ws-security-stax, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jaxrpc-api_1.1_spec, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-openssl-linux, p-cpe:/a:redhat:enterprise_linux:eap7-staxmapper, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jaxrs-api_2.0_spec, p-cpe:/a:redhat:enterprise_linux:eap7-jgroups-azure, p-cpe:/a:redhat:enterprise_linux:eap7-jsoup, p-cpe:/a:redhat:enterprise_linux:eap7-jul-to-slf4j-stub, p-cpe:/a:redhat:enterprise_linux:eap7-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap7-weld-core-impl, p-cpe:/a:redhat:enterprise_linux:eap7-codehaus-jackson-jaxrs, p-cpe:/a:redhat:enterprise_linux:eap7-jaxbintros, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-genericjms, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-websocket-api_1.1_spec, p-cpe:/a:redhat:enterprise_linux:eap7-netty, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-atom-provider, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-client-config, p-cpe:/a:redhat:enterprise_linux:eap7-codehaus-jackson-core-asl, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-el-api_3.0_spec, p-cpe:/a:redhat:enterprise_linux:eap7-neethi, p-cpe:/a:redhat:enterprise_linux:eap7-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-multipart-provider, p-cpe:/a:redhat:enterprise_linux:eap7-vdx-core, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-servlet-api_3.1_spec, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-transaction-api_1.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jackson-provider, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata-ear, p-cpe:/a:redhat:enterprise_linux:eap7-cxf-xjc-boolean, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap7-java-classmate, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-marshalling-river, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan-commons, p-cpe:/a:redhat:enterprise_linux:eap7-antlr, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap6.4-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-weld-core-jsf, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-openssl-java, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-ws-security-policy-stax, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jaxws-api_2.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-concurrent, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-native, p-cpe:/a:redhat:enterprise_linux:eap7-guava, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly8.2, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-ra, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-classfilewriter, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-jts-integration, p-cpe:/a:redhat:enterprise_linux:eap7-artemis-native, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-weld-2.2-api, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-validator-provider-11, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j, p-cpe:/a:redhat:enterprise_linux:eap7-artemis-native-wildfly, p-cpe:/a:redhat:enterprise_linux:eap7-joda-time, p-cpe:/a:redhat:enterprise_linux:eap7-taglibs-standard-compat, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jsp-api_2.3_spec, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-validator, p-cpe:/a:redhat:enterprise_linux:eap7-apache-cxf-xjc-utils, p-cpe:/a:redhat:enterprise_linux:eap7-codemodel, p-cpe:/a:redhat:enterprise_linux:eap7-mod_cluster, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap6.4, p-cpe:/a:redhat:enterprise_linux:eap7-objectweb-asm, p-cpe:/a:redhat:enterprise_linux:eap7-txw2, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-discovery-client, p-cpe:/a:redhat:enterprise_linux:eap7-javassist, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap7.0-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-restat-integration, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly8.2-to-eap7.0, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-compensations, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap7.0, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-yaml-provider, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata-common, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata-web, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-security-xacml, p-cpe:/a:redhat:enterprise_linux:eap7-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-ws-security-common, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-javamail, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search-engine, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap7-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-ejb3-ext-api, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-jaf, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-concurrency-api_1.0_spec, p-cpe:/a:redhat:enterprise_linux:eap7-cxf-xjc-runtime, p-cpe:/a:redhat:enterprise_linux:eap7-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap7-codehaus-jackson, p-cpe:/a:redhat:enterprise_linux:eap7-picketbox-commons, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-ejb-client, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-infinispan, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap7-cxf-xjc-ts, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-naming-client, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-json, p-cpe:/a:redhat:enterprise_linux:eap7-httpcomponents-client, p-cpe:/a:redhat:enterprise_linux:eap7-jaxen, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search-serialization-avro, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-policy, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap7-elytron-web, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-logmanager, p-cpe:/a:redhat:enterprise_linux:eap7-jansi, p-cpe:/a:redhat:enterprise_linux:eap7-apache-mime4j, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-jts-idlj, p-cpe:/a:redhat:enterprise_linux:eap7-picketbox, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jsapi, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search, p-cpe:/a:redhat:enterprise_linux:eap7-taglibs-standard-spec, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-invocation, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-discovery, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-core, p-cpe:/a:redhat:enterprise_linux:eap7-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap7-netty-xnio-transport, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-validator-cdi, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-entitymanager, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search-orm, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-jaxb, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan-cachestore-remote, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jms-server, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-crypto, p-cpe:/a:redhat:enterprise_linux:eap7-httpcomponents-core, p-cpe:/a:redhat:enterprise_linux:eap7-apache-commons-cli, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-el-impl, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata-appclient, p-cpe:/a:redhat:enterprise_linux:eap7-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan-client-hotrod, p-cpe:/a:redhat:enterprise_linux:eap7-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly9.0, p-cpe:/a:redhat:enterprise_linux:eap7-mustache-java, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-restat-util, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap7-woodstox-core, p-cpe:/a:redhat:enterprise_linux:eap7-azure-storage, p-cpe:/a:redhat:enterprise_linux:eap7-jettison, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-xnio-base, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-http-transaction-client, p-cpe:/a:redhat:enterprise_linux:eap7-codehaus-jackson-xc, p-cpe:/a:redhat:enterprise_linux:eap7-bouncycastle-pkix, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly9.0-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-http-client, p-cpe:/a:redhat:enterprise_linux:eap7-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-interceptors-api_1.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-jbossxts, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-transaction-spi, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-dmr, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-modules, p-cpe:/a:redhat:enterprise_linux:eap7-tomcat-taglibs-standard, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search-backend-jms, p-cpe:/a:redhat:enterprise_linux:eap7-xom, p-cpe:/a:redhat:enterprise_linux:eap7-undertow-jastow, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-cli, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jaxrs, p-cpe:/a:redhat:enterprise_linux:eap7-xml-security, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jaxb-api_2.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-txframework, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan-cachestore-jdbc, p-cpe:/a:redhat:enterprise_linux:eap7-netty-all, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly9.0-to-eap7.0, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-marshalling, p-cpe:/a:redhat:enterprise_linux:eap7-snakeyaml, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-metadata, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly10.1, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-http-naming-client, p-cpe:/a:redhat:enterprise_linux:eap7-guava-libraries, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly10.0-to-eap7.1, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jms-api_2.0_spec, p-cpe:/a:redhat:enterprise_linux:eap7-slf4j, p-cpe:/a:redhat:enterprise_linux:eap7-sun-ws-metadata-2.0-api, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-remoting-jmx, p-cpe:/a:redhat:enterprise_linux:eap7-slf4j-ext, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap7-bouncycastle, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-jsf-api_2.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-connector-api_1.7_spec, p-cpe:/a:redhat:enterprise_linux:eap7-rngom, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-module-jaxb-annotations, p-cpe:/a:redhat:enterprise_linux:eap7-jandex, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-transaction-client, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-commons-annotations, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-jsf, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap7-undertow, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-http-ejb-client, p-cpe:/a:redhat:enterprise_linux:eap7-picketbox-infinispan, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-search-backend-jgroups, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap7-sun-saaj-1.3-impl, p-cpe:/a:redhat:enterprise_linux:eap7-apache-commons-io, p-cpe:/a:redhat:enterprise_linux:eap7-jberet, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-jpa-2.1-api, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-wildfly10.0, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-ejb-api_3.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-undertow-server, p-cpe:/a:redhat:enterprise_linux:eap7-narayana, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jaxb-provider, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-cdi, p-cpe:/a:redhat:enterprise_linux:eap7-h2database, p-cpe:/a:redhat:enterprise_linux:eap7-weld-probe-core, p-cpe:/a:redhat:enterprise_linux:eap7-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap7-jberet-core, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-iiop-client, p-cpe:/a:redhat:enterprise_linux:eap7-narayana-jbosstxbridge, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-spring, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-ws-security-dom, p-cpe:/a:redhat:enterprise_linux:eap7-infinispan-core, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jms-client, p-cpe:/a:redhat:enterprise_linux:eap7-bouncycastle-prov, p-cpe:/a:redhat:enterprise_linux:eap7-bouncycastle-mail, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-openjdk-orb, p-cpe:/a:redhat:enterprise_linux:eap7-vdx, p-cpe:/a:redhat:enterprise_linux:eap7-hibernate-java8, p-cpe:/a:redhat:enterprise_linux:eap7-codehaus-jackson-mapper-asl, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-annotations-api_1.2_spec, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-jackson2-provider, p-cpe:/a:redhat:enterprise_linux:eap7-taglibs-standard-impl, p-cpe:/a:redhat:enterprise_linux:eap7-weld-core, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-http-client-common, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-web-console-eap, p-cpe:/a:redhat:enterprise_linux:eap7-vdx-wildfly, p-cpe:/a:redhat:enterprise_linux:eap7-wss4j-bindings, p-cpe:/a:redhat:enterprise_linux:eap7-jbossws-common-tools, p-cpe:/a:redhat:enterprise_linux:eap7-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap7-cxf-xjc-bug986, p-cpe:/a:redhat:enterprise_linux:eap7-ecj, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap7-resteasy-json-p-provider

必要的 KB 項目: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2017/12/13

弱點發布日期: 2016/9/26

參考資訊

CVE: CVE-2016-4978, CVE-2016-4993, CVE-2016-5406, CVE-2016-6311, CVE-2016-7046, CVE-2016-7061, CVE-2016-8627, CVE-2016-8656, CVE-2016-9589, CVE-2017-12165, CVE-2017-12167, CVE-2017-2595, CVE-2017-2666, CVE-2017-2670, CVE-2017-7525, CVE-2017-7536, CVE-2017-7559

CWE: 113, 119, 20, 200, 22, 284, 400, 444, 732, 835

RHSA: 2017:3454