<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bug in der commons-collection library - effects for JBOSS in SAS Web Application unclear in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243504#M3906</link>
    <description>&lt;P&gt;Hi Gunnar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I highly recommend reading through this note if it applies to your version of JBoss:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://access.redhat.com/solutions/30744" target="_blank"&gt;https://access.redhat.com/solutions/30744&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's an older vulnerability with a poorly secured JMX console. Although you should be ok if you're running on an internal network and/or non-standard port, you should exercise extreme caution if you're running a publically accessible SAS server without a reverse proxy. I've had to chase a couple of trojans down, it's not fun. The fix in that link is relatively straightforward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nik&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2016 16:20:21 GMT</pubDate>
    <dc:creator>boemskats</dc:creator>
    <dc:date>2016-01-14T16:20:21Z</dc:date>
    <item>
      <title>Bug in der commons-collection library - effects for JBOSS in SAS Web Application unclear</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243138#M3882</link>
      <description>&lt;P&gt;Hi Guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a rather general question. There is a security bug which affects the JBOSS-Servers (check: &lt;A href="https://bugzilla.redhat.com/show_bug.cgi?id=1279330)." target="_blank"&gt;https://bugzilla.redhat.com/show_bug.cgi?id=1279330).&lt;/A&gt; A lot of SAS-Webapplications are using&amp;nbsp;JBOSS, i wonder what effect this may have on these applications.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gunnar&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 08:52:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243138#M3882</guid>
      <dc:creator>Gkrause</dc:creator>
      <dc:date>2016-01-13T08:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in der commons-collection library - effects for JBOSS in SAS Web Application unclear</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243462#M3896</link>
      <description>&lt;P&gt;Hi Gunnar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please take a look at the folllowing link. Is this what you are looking for?&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/security/Java-deserialization.html" target="_blank"&gt;http://support.sas.com/security/Java-deserialization.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anja&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 13:15:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243462#M3896</guid>
      <dc:creator>anja</dc:creator>
      <dc:date>2016-01-14T13:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in der commons-collection library - effects for JBOSS in SAS Web Application unclear</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243504#M3906</link>
      <description>&lt;P&gt;Hi Gunnar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I highly recommend reading through this note if it applies to your version of JBoss:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://access.redhat.com/solutions/30744" target="_blank"&gt;https://access.redhat.com/solutions/30744&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's an older vulnerability with a poorly secured JMX console. Although you should be ok if you're running on an internal network and/or non-standard port, you should exercise extreme caution if you're running a publically accessible SAS server without a reverse proxy. I've had to chase a couple of trojans down, it's not fun. The fix in that link is relatively straightforward.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nik&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 16:20:21 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243504#M3906</guid>
      <dc:creator>boemskats</dc:creator>
      <dc:date>2016-01-14T16:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Bug in der commons-collection library - effects for JBOSS in SAS Web Application unclear</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243709#M3911</link>
      <description>&lt;P&gt;Hi Anja,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes this is exatctly the issue but the link does not show any solution. It is just a notification that sas knows about the issue.&lt;/P&gt;&lt;P&gt;Anyhow...I am not really sure if this is a SAS responsibility or if the people behind JBoss must act here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Gunnar&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 09:18:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Bug-in-der-commons-collection-library-effects-for-JBOSS-in-SAS/m-p/243709#M3911</guid>
      <dc:creator>Gkrause</dc:creator>
      <dc:date>2016-01-15T09:18:49Z</dc:date>
    </item>
  </channel>
</rss>

