PT-2017-3950 · Red Hat · Red Hat Jboss Eap

Jason Shepherd

·

Published

2017-09-13

·

Updated

2022-05-13

·

CVE-2017-7561

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss EAP versions 3.0.7 through 3.0.25.Final Red Hat JBoss EAP version 3.5.0.CR1 Red Hat JBoss EAP version 4.0.0.Beta1
Description The issue is related to inconsistent interpretation of HTTP requests, which can be exploited by a remote attacker to compromise data integrity. This can result in server-side cache poisoning or CORS requests in the JAX-RS component.
Recommendations For Red Hat JBoss EAP versions 3.0.7 through 3.0.25.Final, consider updating to a version outside of this range to mitigate the risk. For Red Hat JBoss EAP version 3.5.0.CR1, consider updating to a version outside of this range to mitigate the risk. For Red Hat JBoss EAP version 4.0.0.Beta1, consider updating to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the JAX-RS component to minimize the risk of exploitation.

Fix

Origin Validation Error

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02915
CVE-2017-7561
GHSA-57Q5-X8JF-G7H8
RHSA-2018:0002
RHSA-2018:0004
RHSA-2018:0005
RHSA-2018:0479
RHSA-2018:0480
RHSA-2018:0481

Affected Products

Red Hat Jboss Eap