Hide Forgot
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Carlo de Wolf <cdewolf> updated the status of jira JBEAP-2072 to Resolved
Acknowledgments: Name: Dennis Reed (Red Hat)
This issue has been addressed in the following products: JBoss Data Grid 6.6 Via RHSA-2016:1334 https://access.redhat.com/errata/RHSA-2016:1334
This issue has been addressed in the following products: JBoss Enterprise Application Platform 7.0 Via RHSA-2016:1333 https://rhn.redhat.com/errata/RHSA-2016-1333.html
This issue has been addressed in the following products: JBEAP 7.0.z for RHEL 7 JBEAP 7.0.z for RHEL 6 Via RHSA-2016:1332 https://access.redhat.com/errata/RHSA-2016:1332
This issue has been addressed in the following products: JBoss Enterprise Application Platform 6.4 Via RHSA-2016:1331 https://rhn.redhat.com/errata/RHSA-2016-1331.html
This issue has been addressed in the following products: JBoss Enterprise Application Platform 5.2 Via RHSA-2016:1329 https://rhn.redhat.com/errata/RHSA-2016-1329.html
This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 6 JBEAP 6.4.z for RHEL 5 JBEAP 6.4.z for RHEL 7 Via RHSA-2016:1330 https://access.redhat.com/errata/RHSA-2016:1330
This issue has been addressed in the following products: JBEAP 5 for RHEL 5 JBEAP 5 for RHEL 4 JBEAP 5 for RHEL 6 Via RHSA-2016:1328 https://access.redhat.com/errata/RHSA-2016:1328
Mitigation: Please refer to https://access.redhat.com/articles/2360521 for more information.
This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.3 Via RHSA-2016:1347 https://access.redhat.com/errata/RHSA-2016:1347
This issue has been addressed in the following products: Red Hat JBoss Data Virtualization 6.2 Via RHSA-2016:1346 https://access.redhat.com/errata/RHSA-2016:1346
This issue has been addressed in the following products: Red Hat JBoss BRMS 6.3 Via RHSA-2016:1345 https://access.redhat.com/errata/RHSA-2016:1345
This issue has been addressed in the following products: Red Hat JBoss Portal 6.2.0 Via RHSA-2016:1374 https://access.redhat.com/errata/RHSA-2016:1374
This issue has been addressed in the following products: Red Hat JBoss SOA Platform 5.3.1 Via RHSA-2016:1376 https://access.redhat.com/errata/RHSA-2016:1376
This issue has been addressed in the following products: Red Hat JBoss Fuse Service Works 6.0.0 Via RHSA-2016:1389 https://access.redhat.com/errata/RHSA-2016:1389
This issue has been addressed in the following products: JBoss Enterprise BRMS Platform 5.3 Via RHSA-2016:1435 https://access.redhat.com/errata/RHSA-2016:1435
This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 7 Via RHSA-2016:1434 https://access.redhat.com/errata/RHSA-2016:1434
This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 6 Via RHSA-2016:1432 https://access.redhat.com/errata/RHSA-2016:1432
This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 6 Via RHSA-2016:1433 https://access.redhat.com/errata/RHSA-2016:1433
This issue has been addressed in the following products: Red Hat Single Sign-On Via RHSA-2016:1439 https://rhn.redhat.com/errata/RHSA-2016-1439.html
Jiri Pallich <jpallich> updated the status of jira JBEAP-2072 to Closed
This issue has been addressed in the following products: Red Hat JBoss Fuse 6.3 Via RHSA-2016:2035 https://rhn.redhat.com/errata/RHSA-2016-2035.html