Vulnerabilities > CVE-2016-2094 - Resource Management Errors vulnerability in Jboss Enterprise Application Platform 6.4.6

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
jboss
CWE-399
nessus

Summary

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

Vulnerable Configurations

Part Description Count
Application
Jboss
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2016-0596.NASL
    descriptionA Red Hat JBoss Enterprise Application Platform update is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. This release serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.6, and includes bug fixes and enhancements. Documentation for these changes will be available shortly from the Red Hat JBoss Enterprise Application Platform 6.4.7 Release Notes, linked to in the References. Security Fix(es) : * A read-timeout flaw was found in the HTTPS NIO Connector handling of SSL handshakes. A remote, unauthenticated attacker could create a socket and cause a thread to remain occupied indefinitely so long as the socket remained open (denial of service). (CVE-2016-2094) * It was found that Tomcat would keep connections open after processing requests with a large enough request body. A remote attacker could potentially use this flaw to exhaust the pool of available connections and preventing further, legitimate connections to the Tomcat server to be made. (CVE-2014-0230) The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat.
    last seen2020-06-01
    modified2020-06-02
    plugin id90389
    published2016-04-07
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/90389
    titleRHEL 6 : JBoss EAP (RHSA-2016:0596)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were  
    # extracted from Red Hat Security Advisory RHSA-2016:0596. The text 
    # itself is copyright (C) Red Hat, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(90389);
      script_version("2.12");
      script_cvs_date("Date: 2019/10/24 15:35:41");
    
      script_cve_id("CVE-2014-0230", "CVE-2016-2094");
      script_xref(name:"RHSA", value:"2016:0596");
    
      script_name(english:"RHEL 6 : JBoss EAP (RHSA-2016:0596)");
      script_summary(english:"Checks the rpm output for the updated packages");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote Red Hat host is missing one or more security updates."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "A Red Hat JBoss Enterprise Application Platform update is now
    available for Red Hat Enterprise Linux 6.
    
    Red Hat Product Security has rated this update as having a security
    impact of Moderate. A Common Vulnerability Scoring System (CVSS) base
    score, which gives a detailed severity rating, is available for each
    vulnerability from the CVE link(s) in the References section.
    
    Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
    applications based on JBoss Application Server 7.
    
    This release serves as a replacement for Red Hat JBoss Enterprise
    Application Platform 6.4.6, and includes bug fixes and enhancements.
    Documentation for these changes will be available shortly from the Red
    Hat JBoss Enterprise Application Platform 6.4.7 Release Notes, linked
    to in the References.
    
    Security Fix(es) :
    
    * A read-timeout flaw was found in the HTTPS NIO Connector handling of
    SSL handshakes. A remote, unauthenticated attacker could create a
    socket and cause a thread to remain occupied indefinitely so long as
    the socket remained open (denial of service). (CVE-2016-2094)
    
    * It was found that Tomcat would keep connections open after
    processing requests with a large enough request body. A remote
    attacker could potentially use this flaw to exhaust the pool of
    available connections and preventing further, legitimate connections
    to the Tomcat server to be made. (CVE-2014-0230)
    
    The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/errata/RHSA-2016:0596"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2014-0230"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2016-2094"
      );
      script_set_attribute(attribute:"solution", value:"Update the affected packages.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
      script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H");
      script_set_cvss3_temporal_vector("CVSS:3.0/E:U/RL:O/RC:C");
      script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"false");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:glassfish-jsf-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:hornetq");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:infinispan");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:infinispan-cachestore-jdbc");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:infinispan-cachestore-remote");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:infinispan-client-hotrod");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:infinispan-core");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-common-api-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-common-impl-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-common-spi-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-core-api-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-core-impl-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-deployers-common-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-jdbc-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-spec-api-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:ironjacamar-validator-eap6");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-appclient");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-cli");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-client-all");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-clustering");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-cmp");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-configadmin");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-connector");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-console");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-controller");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-controller-client");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-core-security");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-deployment-repository");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-deployment-scanner");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-domain-http");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-domain-management");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-ee");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-ee-deployment");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-ejb3");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-embedded");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-host-controller");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jacorb");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jaxr");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jaxrs");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jdr");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jmx");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jpa");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jsf");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-jsr77");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-logging");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-mail");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-management-client-content");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-messaging");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-modcluster");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-naming");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-network");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-osgi");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-osgi-configadmin");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-osgi-service");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-picketlink");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-platform-mbean");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-pojo");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-process-controller");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-protocol");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-remoting");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-sar");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-security");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-server");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-system-jmx");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-threads");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-transactions");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-version");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-web");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-webservices");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-weld");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-as-xts");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-hal");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-security-negotiation");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-appclient");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-bundles");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-core");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-domain");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-javadocs");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-modules-eap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-product-eap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-standalone");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossas-welcome-content-eap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jbossweb");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:resteasy");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:weld-core");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:redhat:enterprise_linux:6");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2015/06/07");
      script_set_attribute(attribute:"patch_publication_date", value:"2016/04/05");
      script_set_attribute(attribute:"plugin_publication_date", value:"2016/04/07");
      script_set_attribute(attribute:"generated_plugin", value:"current");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"Red Hat Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list", "Host/cpu");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    include("rpm.inc");
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    release = get_kb_item("Host/RedHat/release");
    if (isnull(release) || "Red Hat" >!< release) audit(AUDIT_OS_NOT, "Red Hat");
    os_ver = pregmatch(pattern: "Red Hat Enterprise Linux.*release ([0-9]+(\.[0-9]+)?)", string:release);
    if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Red Hat");
    os_ver = os_ver[1];
    if (! preg(pattern:"^6([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Red Hat 6.x", "Red Hat " + os_ver);
    
    if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    cpu = get_kb_item("Host/cpu");
    if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
    if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$" && "s390" >!< cpu) audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Red Hat", cpu);
    
    yum_updateinfo = get_kb_item("Host/RedHat/yum-updateinfo");
    if (!empty_or_null(yum_updateinfo)) 
    {
      rhsa = "RHSA-2016:0596";
      yum_report = redhat_generate_yum_updateinfo_report(rhsa:rhsa);
      if (!empty_or_null(yum_report))
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : yum_report 
        );
        exit(0);
      }
      else
      {
        audit_message = "affected by Red Hat security advisory " + rhsa;
        audit(AUDIT_OS_NOT, audit_message);
      }
    }
    else
    {
      flag = 0;
    
      if (! (rpm_exists(release:"RHEL6", rpm:"jbossas-welcome-content-eap"))) audit(AUDIT_PACKAGE_NOT_INSTALLED, "JBoss EAP");
    
      if (rpm_check(release:"RHEL6", reference:"glassfish-jsf-eap6-2.1.28-10.SP9_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"hornetq-2.3.25-11.SP9_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"infinispan-5.2.18-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"infinispan-cachestore-jdbc-5.2.18-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"infinispan-cachestore-remote-5.2.18-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"infinispan-client-hotrod-5.2.18-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"infinispan-core-5.2.18-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-common-api-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-common-impl-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-common-spi-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-core-api-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-core-impl-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-deployers-common-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-jdbc-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-spec-api-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"ironjacamar-validator-eap6-1.0.36-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-appclient-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-cli-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-client-all-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-clustering-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-cmp-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-configadmin-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-connector-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-console-2.5.12-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-controller-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-controller-client-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-core-security-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-deployment-repository-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-deployment-scanner-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-domain-http-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-domain-management-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-ee-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-ee-deployment-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-ejb3-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-embedded-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-host-controller-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jacorb-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jaxr-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jaxrs-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jdr-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jmx-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jpa-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jsf-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-jsr77-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-logging-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-mail-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-management-client-content-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-messaging-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-modcluster-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-naming-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-network-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-osgi-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-osgi-configadmin-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-osgi-service-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-picketlink-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-platform-mbean-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-pojo-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-process-controller-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-protocol-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-remoting-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-sar-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-security-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-server-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-system-jmx-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-threads-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-transactions-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-version-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-web-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-webservices-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-weld-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-as-xts-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-hal-2.5.12-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-security-negotiation-2.3.11-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-appclient-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-bundles-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-core-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-domain-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-javadocs-7.5.7-3.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-modules-eap-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-product-eap-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-standalone-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossas-welcome-content-eap-7.5.7-2.Final_redhat_3.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jbossweb-7.5.15-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"resteasy-2.3.13-1.Final_redhat_1.1.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"weld-core-1.1.33-1.Final_redhat_1.1.ep6.el6")) flag++;
    
      if (flag)
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : rpm_report_get() + redhat_report_package_caveat()
        );
        exit(0);
      }
      else
      {
        tested = pkg_tests_get();
        if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested);
        else audit(AUDIT_PACKAGE_NOT_INSTALLED, "glassfish-jsf-eap6 / hornetq / infinispan / etc");
      }
    }
    
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2016-0598.NASL
    descriptionA jboss-ec2-eap update is now available for Red Hat JBoss Enterprise Application Platform 6.4.7 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. The jboss-ec2-eap packages provide scripts for Red Hat JBoss Enterprise Application Platform running on the Amazon Web Services (AWS) Elastic Compute Cloud (EC2). With this update, the packages have been updated to ensure compatibility with Red Hat JBoss Enterprise Application Platform 6.4.7. Security Fix(es) : * A read-timeout flaw was found in the HTTPS NIO Connector handling of SSL handshakes. A remote, unauthenticated attacker could create a socket and cause a thread to remain occupied indefinitely so long as the socket remained open (denial of service). (CVE-2016-2094) * It was found that Tomcat would keep connections open after processing requests with a large enough request body. A remote attacker could potentially use this flaw to exhaust the pool of available connections and preventing further, legitimate connections to the Tomcat server to be made. (CVE-2014-0230) The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat.
    last seen2020-06-01
    modified2020-06-02
    plugin id90390
    published2016-04-07
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/90390
    titleRHEL 6 : jboss-ec2-eap (RHSA-2016:0598)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were  
    # extracted from Red Hat Security Advisory RHSA-2016:0598. The text 
    # itself is copyright (C) Red Hat, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(90390);
      script_version("2.12");
      script_cvs_date("Date: 2019/10/24 15:35:41");
    
      script_cve_id("CVE-2014-0230", "CVE-2016-2094");
      script_xref(name:"RHSA", value:"2016:0598");
    
      script_name(english:"RHEL 6 : jboss-ec2-eap (RHSA-2016:0598)");
      script_summary(english:"Checks the rpm output for the updated packages");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote Red Hat host is missing one or more security updates."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "A jboss-ec2-eap update is now available for Red Hat JBoss Enterprise
    Application Platform 6.4.7 on Red Hat Enterprise Linux 6.
    
    Red Hat Product Security has rated this update as having a security
    impact of Moderate. A Common Vulnerability Scoring System (CVSS) base
    score, which gives a detailed severity rating, is available for each
    vulnerability from the CVE link(s) in the References section.
    
    Red Hat JBoss Enterprise Application Platform 6 is a platform for Java
    applications based on JBoss Application Server 7.
    
    The jboss-ec2-eap packages provide scripts for Red Hat JBoss
    Enterprise Application Platform running on the Amazon Web Services
    (AWS) Elastic Compute Cloud (EC2). With this update, the packages have
    been updated to ensure compatibility with Red Hat JBoss Enterprise
    Application Platform 6.4.7.
    
    Security Fix(es) :
    
    * A read-timeout flaw was found in the HTTPS NIO Connector handling of
    SSL handshakes. A remote, unauthenticated attacker could create a
    socket and cause a thread to remain occupied indefinitely so long as
    the socket remained open (denial of service). (CVE-2016-2094)
    
    * It was found that Tomcat would keep connections open after
    processing requests with a large enough request body. A remote
    attacker could potentially use this flaw to exhaust the pool of
    available connections and preventing further, legitimate connections
    to the Tomcat server to be made. (CVE-2014-0230)
    
    The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat."
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/errata/RHSA-2016:0598"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2014-0230"
      );
      script_set_attribute(
        attribute:"see_also",
        value:"https://access.redhat.com/security/cve/cve-2016-2094"
      );
      script_set_attribute(
        attribute:"solution", 
        value:
    "Update the affected jboss-ec2-eap and / or jboss-ec2-eap-samples
    packages."
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
      script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H");
      script_set_cvss3_temporal_vector("CVSS:3.0/E:U/RL:O/RC:C");
      script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"false");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-ec2-eap");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:jboss-ec2-eap-samples");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:redhat:enterprise_linux:6");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2015/06/07");
      script_set_attribute(attribute:"patch_publication_date", value:"2016/04/05");
      script_set_attribute(attribute:"plugin_publication_date", value:"2016/04/07");
      script_set_attribute(attribute:"generated_plugin", value:"current");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"Red Hat Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list", "Host/cpu");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("misc_func.inc");
    include("rpm.inc");
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    release = get_kb_item("Host/RedHat/release");
    if (isnull(release) || "Red Hat" >!< release) audit(AUDIT_OS_NOT, "Red Hat");
    os_ver = pregmatch(pattern: "Red Hat Enterprise Linux.*release ([0-9]+(\.[0-9]+)?)", string:release);
    if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Red Hat");
    os_ver = os_ver[1];
    if (! preg(pattern:"^6([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Red Hat 6.x", "Red Hat " + os_ver);
    
    if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    cpu = get_kb_item("Host/cpu");
    if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH);
    if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$" && "s390" >!< cpu) audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Red Hat", cpu);
    
    yum_updateinfo = get_kb_item("Host/RedHat/yum-updateinfo");
    if (!empty_or_null(yum_updateinfo)) 
    {
      rhsa = "RHSA-2016:0598";
      yum_report = redhat_generate_yum_updateinfo_report(rhsa:rhsa);
      if (!empty_or_null(yum_report))
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : yum_report 
        );
        exit(0);
      }
      else
      {
        audit_message = "affected by Red Hat security advisory " + rhsa;
        audit(AUDIT_OS_NOT, audit_message);
      }
    }
    else
    {
      flag = 0;
      if (rpm_check(release:"RHEL6", reference:"jboss-ec2-eap-7.5.7-2.Final_redhat_3.ep6.el6")) flag++;
      if (rpm_check(release:"RHEL6", reference:"jboss-ec2-eap-samples-7.5.7-2.Final_redhat_3.ep6.el6")) flag++;
    
      if (flag)
      {
        security_report_v4(
          port       : 0,
          severity   : SECURITY_HOLE,
          extra      : rpm_report_get() + redhat_report_package_caveat()
        );
        exit(0);
      }
      else
      {
        tested = pkg_tests_get();
        if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested);
        else audit(AUDIT_PACKAGE_NOT_INSTALLED, "jboss-ec2-eap / jboss-ec2-eap-samples");
      }
    }
    
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2016-0597.NASL
    descriptionA Red Hat JBoss Enterprise Application Platform update is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. This release serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.6, and includes bug fixes and enhancements. Documentation for these changes will be available shortly from the Red Hat JBoss Enterprise Application Platform 6.4.7 Release Notes, linked to in the References. Security Fix(es) : * A read-timeout flaw was found in the HTTPS NIO Connector handling of SSL handshakes. A remote, unauthenticated attacker could create a socket and cause a thread to remain occupied indefinitely so long as the socket remained open (denial of service). (CVE-2016-2094) * It was found that Tomcat would keep connections open after processing requests with a large enough request body. A remote attacker could potentially use this flaw to exhaust the pool of available connections and preventing further, legitimate connections to the Tomcat server to be made. (CVE-2014-0230) The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat.
    last seen2020-06-01
    modified2020-06-02
    plugin id90990
    published2016-05-09
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/90990
    titleRHEL 7 : JBoss EAP (RHSA-2016:0597)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2016-0595.NASL
    descriptionA Red Hat JBoss Enterprise Application Platform update is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. This release serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.6, and includes bug fixes and enhancements. Documentation for these changes will be available shortly from the Red Hat JBoss Enterprise Application Platform 6.4.7 Release Notes, linked to in the References. Security Fix(es) : * A read-timeout flaw was found in the HTTPS NIO Connector handling of SSL handshakes. A remote, unauthenticated attacker could create a socket and cause a thread to remain occupied indefinitely so long as the socket remained open (denial of service). (CVE-2016-2094) * It was found that Tomcat would keep connections open after processing requests with a large enough request body. A remote attacker could potentially use this flaw to exhaust the pool of available connections and preventing further, legitimate connections to the Tomcat server to be made. (CVE-2014-0230) The CVE-2016-2094 issue was discovered by Aaron Ogburn of Red Hat.
    last seen2020-06-01
    modified2020-06-02
    plugin id90388
    published2016-04-07
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/90388
    titleRHEL 5 : JBoss EAP (RHSA-2016:0595)

Redhat

advisories
  • rhsa
    idRHSA-2016:0595
  • rhsa
    idRHSA-2016:0596
  • rhsa
    idRHSA-2016:0597
  • rhsa
    idRHSA-2016:0598
  • rhsa
    idRHSA-2016:0599
rpms
  • glassfish-jsf-eap6-0:2.1.28-10.SP9_redhat_1.1.ep6.el5
  • hornetq-0:2.3.25-11.SP9_redhat_1.1.ep6.el5
  • infinispan-0:5.2.18-1.Final_redhat_1.1.ep6.el5
  • infinispan-cachestore-jdbc-0:5.2.18-1.Final_redhat_1.1.ep6.el5
  • infinispan-cachestore-remote-0:5.2.18-1.Final_redhat_1.1.ep6.el5
  • infinispan-client-hotrod-0:5.2.18-1.Final_redhat_1.1.ep6.el5
  • infinispan-core-0:5.2.18-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-common-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-common-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-common-spi-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-core-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-core-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-deployers-common-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-jdbc-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-spec-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • ironjacamar-validator-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el5
  • jboss-as-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-cli-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-client-all-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-clustering-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-cmp-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-connector-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-console-0:2.5.12-1.Final_redhat_1.1.ep6.el5
  • jboss-as-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-controller-client-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-core-security-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-deployment-repository-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-deployment-scanner-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-domain-http-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-domain-management-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-ee-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-ee-deployment-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-ejb3-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-embedded-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-host-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jacorb-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jaxr-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jaxrs-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jdr-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jpa-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jsf-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-jsr77-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-logging-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-mail-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-management-client-content-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-messaging-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-modcluster-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-naming-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-network-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-osgi-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-osgi-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-osgi-service-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-picketlink-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-platform-mbean-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-pojo-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-process-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-protocol-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-remoting-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-sar-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-security-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-server-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-system-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-threads-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-transactions-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-version-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-web-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-webservices-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-weld-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-as-xts-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jboss-hal-0:2.5.12-1.Final_redhat_1.1.ep6.el5
  • jboss-security-negotiation-0:2.3.11-1.Final_redhat_1.1.ep6.el5
  • jbossas-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-bundles-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-core-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-domain-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-javadocs-0:7.5.7-3.Final_redhat_3.1.ep6.el5
  • jbossas-modules-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-product-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-standalone-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossas-welcome-content-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el5
  • jbossweb-0:7.5.15-1.Final_redhat_1.1.ep6.el5
  • resteasy-0:2.3.13-1.Final_redhat_1.1.ep6.el5
  • weld-core-0:1.1.33-1.Final_redhat_1.1.ep6.el5
  • glassfish-jsf-eap6-0:2.1.28-10.SP9_redhat_1.1.ep6.el6
  • hornetq-0:2.3.25-11.SP9_redhat_1.1.ep6.el6
  • infinispan-0:5.2.18-1.Final_redhat_1.1.ep6.el6
  • infinispan-cachestore-jdbc-0:5.2.18-1.Final_redhat_1.1.ep6.el6
  • infinispan-cachestore-remote-0:5.2.18-1.Final_redhat_1.1.ep6.el6
  • infinispan-client-hotrod-0:5.2.18-1.Final_redhat_1.1.ep6.el6
  • infinispan-core-0:5.2.18-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-common-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-common-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-common-spi-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-core-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-core-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-deployers-common-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-jdbc-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-spec-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • ironjacamar-validator-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el6
  • jboss-as-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-cli-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-client-all-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-clustering-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-cmp-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-connector-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-console-0:2.5.12-1.Final_redhat_1.1.ep6.el6
  • jboss-as-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-controller-client-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-core-security-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-deployment-repository-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-deployment-scanner-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-domain-http-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-domain-management-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-ee-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-ee-deployment-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-ejb3-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-embedded-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-host-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jacorb-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jaxr-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jaxrs-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jdr-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jpa-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jsf-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-jsr77-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-logging-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-mail-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-management-client-content-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-messaging-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-modcluster-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-naming-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-network-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-osgi-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-osgi-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-osgi-service-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-picketlink-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-platform-mbean-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-pojo-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-process-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-protocol-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-remoting-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-sar-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-security-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-server-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-system-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-threads-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-transactions-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-version-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-web-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-webservices-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-weld-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-as-xts-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jboss-hal-0:2.5.12-1.Final_redhat_1.1.ep6.el6
  • jboss-security-negotiation-0:2.3.11-1.Final_redhat_1.1.ep6.el6
  • jbossas-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-bundles-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-core-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-domain-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-javadocs-0:7.5.7-3.Final_redhat_3.1.ep6.el6
  • jbossas-modules-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-product-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-standalone-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossas-welcome-content-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el6
  • jbossweb-0:7.5.15-1.Final_redhat_1.1.ep6.el6
  • resteasy-0:2.3.13-1.Final_redhat_1.1.ep6.el6
  • weld-core-0:1.1.33-1.Final_redhat_1.1.ep6.el6
  • glassfish-jsf-eap6-0:2.1.28-10.SP9_redhat_1.1.ep6.el7
  • hornetq-0:2.3.25-11.SP9_redhat_1.1.ep6.el7
  • infinispan-0:5.2.18-1.Final_redhat_1.1.ep6.el7
  • infinispan-cachestore-jdbc-0:5.2.18-1.Final_redhat_1.1.ep6.el7
  • infinispan-cachestore-remote-0:5.2.18-1.Final_redhat_1.1.ep6.el7
  • infinispan-client-hotrod-0:5.2.18-1.Final_redhat_1.1.ep6.el7
  • infinispan-core-0:5.2.18-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-common-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-common-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-common-spi-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-core-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-core-impl-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-deployers-common-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-jdbc-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-spec-api-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • ironjacamar-validator-eap6-0:1.0.36-1.Final_redhat_1.1.ep6.el7
  • jboss-as-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-cli-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-client-all-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-clustering-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-cmp-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-connector-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-console-0:2.5.12-1.Final_redhat_1.1.ep6.el7
  • jboss-as-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-controller-client-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-core-security-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-deployment-repository-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-deployment-scanner-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-domain-http-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-domain-management-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-ee-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-ee-deployment-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-ejb3-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-embedded-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-host-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jacorb-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jaxr-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jaxrs-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jdr-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jpa-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jsf-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-jsr77-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-logging-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-mail-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-management-client-content-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-messaging-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-modcluster-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-naming-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-network-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-osgi-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-osgi-configadmin-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-osgi-service-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-picketlink-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-platform-mbean-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-pojo-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-process-controller-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-protocol-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-remoting-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-sar-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-security-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-server-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-system-jmx-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-threads-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-transactions-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-version-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-web-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-webservices-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-weld-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-as-xts-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jboss-hal-0:2.5.12-1.Final_redhat_1.1.ep6.el7
  • jboss-security-negotiation-0:2.3.11-1.Final_redhat_1.1.ep6.el7
  • jbossas-appclient-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-bundles-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-core-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-domain-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-javadocs-0:7.5.7-3.Final_redhat_3.1.ep6.el7
  • jbossas-modules-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-product-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-standalone-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossas-welcome-content-eap-0:7.5.7-2.Final_redhat_3.1.ep6.el7
  • jbossweb-0:7.5.15-1.Final_redhat_1.1.ep6.el7
  • resteasy-0:2.3.13-1.Final_redhat_1.1.ep6.el7
  • weld-core-0:1.1.33-1.Final_redhat_1.1.ep6.el7
  • jboss-ec2-eap-0:7.5.7-2.Final_redhat_3.ep6.el6
  • jboss-ec2-eap-samples-0:7.5.7-2.Final_redhat_3.ep6.el6