PT-2017-3950 · Red Hat · Red Hat Jboss Eap

Jason Shepherd

·

Publicado

2017-09-13

·

Atualizado

2022-05-13

·

CVE-2017-7561

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss EAP versions 3.0.7 through 3.0.25.Final Red Hat JBoss EAP version 3.5.0.CR1 Red Hat JBoss EAP version 4.0.0.Beta1
Description The issue is related to inconsistent interpretation of HTTP requests, which can be exploited by a remote attacker to compromise data integrity. This can result in server-side cache poisoning or CORS requests in the JAX-RS component.
Recommendations For Red Hat JBoss EAP versions 3.0.7 through 3.0.25.Final, consider updating to a version outside of this range to mitigate the risk. For Red Hat JBoss EAP version 3.5.0.CR1, consider updating to a version outside of this range to mitigate the risk. For Red Hat JBoss EAP version 4.0.0.Beta1, consider updating to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the JAX-RS component to minimize the risk of exploitation.

Correção

Origin Validation Error

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02915
CVE-2017-7561
GHSA-57Q5-X8JF-G7H8
RHSA-2018:0002
RHSA-2018:0004
RHSA-2018:0005
RHSA-2018:0479
RHSA-2018:0480
RHSA-2018:0481

Produtos afetados

Red Hat Jboss Eap