CERT-In Vulnerability Note
CIVN-2016-0322
Directory Traversal Vulnerability in Red Hat JBoss
Original Issue Date:December 14, 2016
Severity Rating: MEDIUM
Software Affected
- RedHat JBoss Business Process Management (BPM) Suite6.3.3
- Red Hat JBoss Business Rules Management System (BRMS) 6.3
Overview
A Vulnerability has been reported in Red Hat JBoss which could be exploited by a remote attacker to conduct disclosure of information on a targeted system.
Description
The vulnerability exists in Drools Workbench Component of Red Hat JBoss due to improper validation of user supplied input. A remote attacker could exploit this vulnerability by supplying a specially crafted request to bypass directory restrictions and view arbitrary files on targeted system.
Solution
Apply appropriate Security fixes as mentioned in the following vendor advisories.
https://rhn.redhat.com/errata/RHSA-2016-2937.html
https://rhn.redhat.com/errata/RHSA-2016-2938.html
Vendor Information
Redhat
https://rhn.redhat.com/errata/RHSA-2016-2937.html
References
Redhat
https://bugzilla.redhat.com/show_bug.cgi?id=1375757
Securitytracker
http://www.securitytracker.com/id/1037406
CVE Name
CVE-2016-7041
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|