Bug 1120495 (CVE-2014-3558) - CVE-2014-3558 Hibernate Validator: JSM bypass via ReflectionHelper
Summary: CVE-2014-3558 Hibernate Validator: JSM bypass via ReflectionHelper
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-3558
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1120518 1120532 1120513 1120514 1120515 1120516 1120517 1120519 1120520 1120521 1120523 1120524 1120525 1120526 1120527 1120529 1120530 1120531 1160692
Blocks: 1082938 1120498 1138220 1181883 1182419 1187398 1196328
TreeView+ depends on / blocked
 
Reported: 2014-07-17 05:08 UTC by Arun Babu Neelicattu
Modified: 2021-02-17 06:22 UTC (History)
52 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.
Clone Of:
Environment:
Last Closed: 2019-06-08 02:33:59 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1285 0 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 23:54:38 UTC
Red Hat Product Errata RHSA-2014:1286 0 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 23:53:02 UTC
Red Hat Product Errata RHSA-2014:1287 0 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 23:51:56 UTC
Red Hat Product Errata RHSA-2014:1288 0 normal SHIPPED_LIVE Low: Red Hat JBoss Enterprise Application Platform 6.3.1 update 2014-09-23 23:41:35 UTC
Red Hat Product Errata RHSA-2015:0125 0 normal SHIPPED_LIVE Important: Red Hat JBoss Web Framework Kit 2.7.0 update 2015-02-04 22:41:57 UTC
Red Hat Product Errata RHSA-2015:0234 0 normal SHIPPED_LIVE Important: Red Hat JBoss BPM Suite 6.0.3 security update 2015-02-18 03:27:47 UTC
Red Hat Product Errata RHSA-2015:0235 0 normal SHIPPED_LIVE Important: Red Hat JBoss BRMS 6.0.3 security update 2015-02-18 03:27:36 UTC
Red Hat Product Errata RHSA-2015:0720 0 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse Service Works 6.0.0 security update 2015-03-25 01:05:53 UTC

Description Arun Babu Neelicattu 2014-07-17 05:08:35 UTC
IssueDescription:

It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.

Comment 1 Arun Babu Neelicattu 2014-07-17 05:10:57 UTC
Upstream Issue:

https://hibernate.atlassian.net/browse/HV-912

Comment 5 Arun Babu Neelicattu 2014-07-17 07:58:29 UTC
Victims Record:

https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaml

Comment 6 errata-xmlrpc 2014-09-23 19:41:41 UTC
This issue has been addressed in the following products:

  JBoss Enterprise Application Platform 6.3.1

Via RHSA-2014:1288 https://rhn.redhat.com/errata/RHSA-2014-1288.html

Comment 7 errata-xmlrpc 2014-09-23 19:56:48 UTC
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 7

Via RHSA-2014:1287 https://rhn.redhat.com/errata/RHSA-2014-1287.html

Comment 8 errata-xmlrpc 2014-09-23 19:57:23 UTC
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 5

Via RHSA-2014:1286 https://rhn.redhat.com/errata/RHSA-2014-1286.html

Comment 9 errata-xmlrpc 2014-09-23 19:58:01 UTC
This issue has been addressed in the following products:

  JBEAP 6.3.z for RHEL 6

Via RHSA-2014:1285 https://rhn.redhat.com/errata/RHSA-2014-1285.html

Comment 12 errata-xmlrpc 2015-02-04 17:42:18 UTC
This issue has been addressed in the following products:

  JBoss Web Framework Kit 2.7.0

Via RHSA-2015:0125 https://rhn.redhat.com/errata/RHSA-2015-0125.html

Comment 14 errata-xmlrpc 2015-02-17 22:29:40 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BRMS 6.0.3

Via RHSA-2015:0235 https://rhn.redhat.com/errata/RHSA-2015-0235.html

Comment 15 errata-xmlrpc 2015-02-17 22:34:03 UTC
This issue has been addressed in the following products:

  Red Hat JBoss BPM Suite 6.0.3

Via RHSA-2015:0234 https://rhn.redhat.com/errata/RHSA-2015-0234.html

Comment 17 errata-xmlrpc 2015-03-24 21:07:15 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse Service Works 6.0.0

Via RHSA-2015:0720 https://rhn.redhat.com/errata/RHSA-2015-0720.html


Note You need to log in before you can comment on or make changes to this bug.