CVE Vulnerabilities

CVE-2017-7561

Origin Validation Error

Published: Sep 13, 2017 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 3.0.7 (including) 3.0.7 (including)
Jboss_enterprise_application_platform Redhat 3.0.8 (including) 3.0.8 (including)
Jboss_enterprise_application_platform Redhat 3.1.0 (including) 3.1.0 (including)
Jboss_enterprise_application_platform Redhat 3.1.1 (including) 3.1.1 (including)
Jboss_enterprise_application_platform Redhat 3.1.2 (including) 3.1.2 (including)
Jboss_enterprise_application_platform Redhat 3.1.4 (including) 3.1.4 (including)
Jboss_enterprise_application_platform Redhat 3.1.5 (including) 3.1.5 (including)
Jboss_enterprise_application_platform Redhat 3.2.3 (including) 3.2.3 (including)
Jboss_enterprise_application_platform Redhat 3.2.4 (including) 3.2.4 (including)
Jboss_enterprise_application_platform Redhat 3.2.5 (including) 3.2.5 (including)
Jboss_enterprise_application_platform Redhat 3.2.9 (including) 3.2.9 (including)
Jboss_enterprise_application_platform Redhat 3.2.13 (including) 3.2.13 (including)
Jboss_enterprise_application_platform Redhat 3.3.0 (including) 3.3.0 (including)
Jboss_enterprise_application_platform Redhat 3.5.1 (including) 3.5.1 (including)
Red Hat JBoss EAP 7 RedHat resteasy *
Red Hat JBoss EAP 7 RedHat resteasy *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 RedHat eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-activemq-artemis-0:1.1.0-19.SP24_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-hibernate-0:5.0.16-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-ironjacamar-0:1.3.8-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-jboss-remoting-0:4.0.25-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-jboss-xnio-base-0:3.4.7-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-jgroups-0:3.6.12-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-resteasy-0:3.0.19-7.SP5_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-undertow-0:1.3.31-3.Final_redhat_3.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-wildfly-0:7.0.9-4.GA_redhat_3.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-wildfly-javadocs-0:7.0.9-2.GA_redhat_3.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 RedHat eap7-jboss-ec2-eap-0:7.0.9-2.GA_redhat_2.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6 RedHat eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el6 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-activemq-artemis-0:1.5.5.009-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-apache-cxf-0:3.1.13-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-glassfish-jsf-0:2.2.13-6.SP5_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-hibernate-0:5.1.12-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-infinispan-0:8.2.9-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-ironjacamar-0:1.4.7-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-core-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-databind-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-jaxrs-providers-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-module-jaxb-annotations-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jackson-modules-java8-0:2.8.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-logmanager-0:2.0.8-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-server-migration-0:1.0.3-6.Final_redhat_6.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jbossws-cxf-0:5.1.10-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-narayana-0:5.5.31-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-bindings-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-picketlink-federation-0:2.5.5-10.SP9_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-resteasy-0:3.0.25-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-0:1.4.18-4.SP2_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-undertow-jastow-0:2.0.3-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-0:7.1.1-4.GA_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-elytron-0:1.1.8-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-http-client-0:1.0.9-1.Final_redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wildfly-javadocs-0:7.1.1-3.GA_redhat_2.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-wss4j-0:2.1.11-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-xml-security-0:2.0.9-1.redhat_1.1.ep7.el7 *
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7 RedHat eap7-jboss-ec2-eap-0:7.1.1-3.1.GA_redhat_3.ep7.el7 *
Resteasy Ubuntu artful *
Resteasy Ubuntu upstream *
Resteasy Ubuntu zesty *
Resteasy3.0 Ubuntu bionic *
Resteasy3.0 Ubuntu cosmic *
Resteasy3.0 Ubuntu esm-apps/bionic *
Resteasy3.0 Ubuntu upstream *

References