Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1120495 - (CVE-2014-3558) CVE-2014-3558 Hibernate Validator: JSM bypass via ReflectionHelper
CVE-2014-3558 Hibernate Validator: JSM bypass via ReflectionHelper
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20140716,reported=2...
: Security
Depends On: 1120518 1120532 1160692 1120513 1120514 1120515 1120516 1120517 1120519 1120520 1120521 1120523 1120524 1120525 1120526 1120527 1120529 1120530 1120531
Blocks: 1082938 1120498 1138220 1181883 1182419 1187398 1196328
  Show dependency treegraph
 
Reported: 2014-07-17 01:08 EDT by Arun Babu Neelicattu
Modified: 2018-07-18 10:28 EDT (History)
53 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1285 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 19:54:38 EDT
Red Hat Product Errata RHSA-2014:1286 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 19:53:02 EDT
Red Hat Product Errata RHSA-2014:1287 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 19:51:56 EDT
Red Hat Product Errata RHSA-2014:1288 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 19:41:35 EDT
Red Hat Product Errata RHSA-2015:0125 normal SHIPPED_LIVE Important: Red Hat JBoss Web Framework Kit 2.7.0 update 2015-02-04 17:41:57 EST
Red Hat Product Errata RHSA-2015:0234 normal SHIPPED_LIVE Important: Red Hat JBoss BPM Suite 6.0.3 security update 2015-02-17 22:27:47 EST
Red Hat Product Errata RHSA-2015:0235 normal SHIPPED_LIVE Important: Red Hat JBoss BRMS 6.0.3 security update 2015-02-17 22:27:36 EST
Red Hat Product Errata RHSA-2015:0720 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse Service Works 6.0.0 security update 2015-03-24 21:05:53 EDT

  None (edit)
Description Arun Babu Neelicattu 2014-07-17 01:08:35 EDT
IssueDescription:

It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.
Comment 1 Arun Babu Neelicattu 2014-07-17 01:10:57 EDT
Upstream Issue:

https://hibernate.atlassian.net/browse/HV-912
Comment 5 Arun Babu Neelicattu 2014-07-17 03:58:29 EDT
Victims Record:

https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaml
Comment 6 errata-xmlrpc 2014-09-23 15:41:41 EDT
This issue has been addressed in the following products:

  JBoss Enterprise Application Platform 6.3.1

Via RHSA-2014:1288 https://rhn.redhat.com/errata/RHSA-2014-1288.html
Comment 7 errata-xmlrpc 2014-09-23 15:56:48 EDT
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 7

Via RHSA-2014:1287 https://rhn.redhat.com/errata/RHSA-2014-1287.html
Comment 8 errata-xmlrpc 2014-09-23 15:57:23 EDT
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 5

Via RHSA-2014:1286 https://rhn.redhat.com/errata/RHSA-2014-1286.html
Comment 9 errata-xmlrpc 2014-09-23 15:58:01 EDT
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 6

Via RHSA-2014:1285 https://rhn.redhat.com/errata/RHSA-2014-1285.html
Comment 12 errata-xmlrpc 2015-02-04 12:42:18 EST
This issue has been addressed in the following products:

  JBoss Web Framework Kit 2.7.0

Via RHSA-2015:0125 https://rhn.redhat.com/errata/RHSA-2015-0125.html
Comment 14 errata-xmlrpc 2015-02-17 17:29:40 EST
This issue has been addressed in the following products:

  Red Hat JBoss BRMS 6.0.3

Via RHSA-2015:0235 https://rhn.redhat.com/errata/RHSA-2015-0235.html
Comment 15 errata-xmlrpc 2015-02-17 17:34:03 EST
This issue has been addressed in the following products:

  Red Hat JBoss BPM Suite 6.0.3

Via RHSA-2015:0234 https://rhn.redhat.com/errata/RHSA-2015-0234.html
Comment 17 errata-xmlrpc 2015-03-24 17:07:15 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse Service Works 6.0.0

Via RHSA-2015:0720 https://rhn.redhat.com/errata/RHSA-2015-0720.html

Note You need to log in before you can comment on or make changes to this bug.