The vendor explicitly identifies these products as affected by this CVE.
- artemis-server as a component of Red Hat JBoss Enterprise Application Platform 7
- artemis-server as a component of Red Hat JBoss Enterprise Application Platform 8
- artemis-server as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- in Apache Artemis, the REATTACH_SESSION handler performs zero authentication — it looks up the session by name only and calls transferConnection() unconditionally, migrating the authenticated session to the attacker's connection. The hijacked cluster-bridge session inherits full broker-management authority (message injection, topology manipulation, journal access)
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).
