<?xml version="1.0" encoding="utf-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Red Hat Security Advisory: JBoss Enterprise BRMS Platform 5.3.0 update</DocumentTitle>
  <DocumentType>Security Advisory</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>secalert@redhat.com</ContactDetails>
    <IssuingAuthority>Red Hat Security Response Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification><ID>RHSA-2012:1028</ID></Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
       <Revision>
         <Number>1</Number>
         <Date>2012-06-22T01:11:00Z</Date>
         <Description>Current version</Description>
       </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2012-06-22T01:11:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2012-06-22T01:11:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>Red Hat rhsa-to-cvrf 1.0.1484</Engine>
      <Date>2012-06-22T01:21:01Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">
JBoss Enterprise BRMS Platform 5.3.0, which fixes multiple security issues,
various bugs, and adds enhancements is now available from the Red Hat
Customer Portal.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.    </Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
JBoss Enterprise BRMS Platform is a business rules management system for
the management, storage, creation, modification, and deployment of JBoss
Rules. The Java Naming and Directory Interface (JNDI) Java API allows Java
software clients to locate objects or services in an application server.

This release of JBoss Enterprise BRMS Platform 5.3.0 serves as a
replacement for JBoss Enterprise BRMS Platform 5.2.0. It includes various
bug fixes and enhancements which are detailed in the JBoss Enterprise BRMS
Platform 5.3.0 Release Notes. The Release Notes will be available shortly
from https://docs.redhat.com/docs/en-US/index.html

The following security issues are also fixed with this release:

It was found that the JBoss JNDI service allowed unauthenticated, remote
write access by default. The JNDI and HA-JNDI services, and the
HAJNDIFactory invoker servlet were all affected. A remote attacker able to
access the JNDI service (port 1099), HA-JNDI service (port 1100), or the
HAJNDIFactory invoker servlet on a JBoss server could use this flaw to add,
delete, and modify items in the JNDI tree. This could have various,
application-specific impacts. (CVE-2011-4605)

It was found that the invoker servlets, deployed by default via
httpha-invoker, only performed access control on the HTTP GET and POST
methods, allowing remote attackers to make unauthenticated requests by
using different HTTP methods. Due to the second layer of authentication
provided by a security interceptor, this issue is not exploitable on
default installations unless an administrator has misconfigured the
security interceptor or disabled it. (CVE-2011-4085)

When a JGroups channel is started, the JGroups diagnostics service would be
enabled by default with no authentication. This service is exposed via IP
multicast. An attacker on an adjacent network could exploit this flaw to
read diagnostics information. (CVE-2012-2377)

Red Hat would like to thank Christian Schlüter (VIADA) for reporting
CVE-2011-4605.

Warning: Before applying the update, back up your existing JBoss Enterprise
BRMS Platform installation (including its databases, applications,
configuration files, and so on).

All users of JBoss Enterprise BRMS Platform 5.2.0 as provided from the Red
Hat Customer Portal are advised to upgrade to JBoss Enterprise BRMS
Platform 5.3.0.    </Note>
    <Note Title="Terms of Use" Ordinal="3" Type="Legal Disclaimer" xml:lang="en">Please see https://www.redhat.com/footer/terms-of-use.html</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
  <AggregateSeverity Namespace="https://access.redhat.com/security/updates/classification/">Important</AggregateSeverity>
  <DocumentReferences>
    <Reference Type="Self">
       <URL>https://rhn.redhat.com/errata/RHSA-2012-1028.html</URL>
       <Description>https://rhn.redhat.com/errata/RHSA-2012-1028.html</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/security/updates/classification/#important</URL>
       <Description>https://access.redhat.com/security/updates/classification/#important</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=brms&amp;downloadType=distributions</URL>
       <Description>https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=brms&amp;downloadType=distributions</Description>
    </Reference>
    <Reference>
       <URL>https://docs.redhat.com/docs/en-US/index.html</URL>
       <Description>https://docs.redhat.com/docs/en-US/index.html</Description>
    </Reference>
  </DocumentReferences>

  <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that the invoker servlets, deployed by default via httpha-invoker, only performed access control on the HTTP GET and POST methods, allowing remote attackers to make unauthenticated requests by using different HTTP methods. Due to the second layer of authentication provided by a security interceptor, this issue is not exploitable on default installations unless an administrator has misconfigured the security interceptor or disabled it. </Note></Notes>
    <DiscoveryDate>2011-10-26T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2011-11-16T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2011-4085</CVE>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>2.6</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
The References section of this erratum contains a download link (you must
log in to download the update). Before applying the update, back up your
existing JBoss Enterprise BRMS Platform installation (including its
databases, applications, configuration files, and so on).    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1028.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2011-4085.html</URL>
        <Description>CVE-2011-4085</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=750422</URL>
        <Description>bz#750422: CVE-2011-4085 Invoker servlets authentication bypass (HTTP verb tampering)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that the JBoss JNDI service allowed unauthenticated, remote write access by default. The JNDI and HA-JNDI services, and the HAJNDIFactory invoker servlet were all affected. A remote attacker able to access the JNDI service (port 1099), HA-JNDI service (port 1100), or the HAJNDIFactory invoker servlet on a JBoss server could use this flaw to add, delete, and modify items in the JNDI tree. This could have various, application-specific impacts. </Note></Notes>
    <DiscoveryDate>2011-12-07T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-06-20T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2011-4605</CVE>
    <Threats><Threat Type="Impact"><Description>Important</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>7.5</BaseScore>
      <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
The References section of this erratum contains a download link (you must
log in to download the update). Before applying the update, back up your
existing JBoss Enterprise BRMS Platform installation (including its
databases, applications, configuration files, and so on).    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1028.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2011-4605.html</URL>
        <Description>CVE-2011-4605</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=766469</URL>
        <Description>bz#766469: CVE-2011-4605 JNDI: unauthenticated remote write access is permitted by default</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Christian Schlüter (VIADA) for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When a JGroups channel is started, the JGroups diagnostics service would be enabled by default with no authentication. This service is exposed via IP multicast. An attacker on an adjacent network could exploit this flaw to read diagnostics information. </Note></Notes>
    <DiscoveryDate>2012-05-17T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-06-12T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2377</CVE>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>3.3</BaseScore>
      <Vector>AV:A/AC:L/Au:N/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
The References section of this erratum contains a download link (you must
log in to download the update). Before applying the update, back up your
existing JBoss Enterprise BRMS Platform installation (including its
databases, applications, configuration files, and so on).    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1028.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2377.html</URL>
        <Description>CVE-2012-2377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=823392</URL>
        <Description>bz#823392: CVE-2012-2377 JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
