SB2018051129 - Resource exhaustion in JBoss Enterprise Application Platform
Published: May 11, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2016-8627)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.
Remediation
Install update from vendor's website.
References
- http://rhn.redhat.com/errata/RHSA-2017-0170.html
- http://rhn.redhat.com/errata/RHSA-2017-0171.html
- http://rhn.redhat.com/errata/RHSA-2017-0172.html
- http://rhn.redhat.com/errata/RHSA-2017-0173.html
- http://rhn.redhat.com/errata/RHSA-2017-0244.html
- http://rhn.redhat.com/errata/RHSA-2017-0245.html
- http://rhn.redhat.com/errata/RHSA-2017-0246.html
- http://rhn.redhat.com/errata/RHSA-2017-0247.html
- http://rhn.redhat.com/errata/RHSA-2017-0250.html
- http://www.securityfocus.com/bid/95698
- http://www.securitytracker.com/id/1037660
- https://access.redhat.com/errata/RHSA-2017:3454
- https://access.redhat.com/errata/RHSA-2017:3455
- https://access.redhat.com/errata/RHSA-2017:3456
- https://access.redhat.com/errata/RHSA-2017:3458
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8627