Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
Red Hat Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Automation Platform
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat Advanced Cluster Management for Kubernetes
      • Red Hat Quay
      • Red Hat CodeReady Workspaces
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • Runtimes
      • Back
      • Red Hat Runtimes
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat Data Grid
      • Red Hat JBoss Web Server
      • Red Hat Single Sign On
      • Red Hat support for Spring Boot
      • Red Hat build of Node.js
      • Red Hat build of Thorntail
      • Red Hat build of Eclipse Vert.x
      • Red Hat build of OpenJDK
      • Red Hat build of Quarkus
      • Red Hat CodeReady Studio
    • Integration and Automation
      • Back
      • Red Hat Integration
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat 3scale API Management
      • Red Hat JBoss Data Virtualization
      • Red Hat Process Automation
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
    • Support
    • Production Support
    • Development Support
    • Product Life Cycles
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem Catalog
    • Partner Resources
    • Red Hat in the Public Cloud
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • 한국어
    • 日本語
    • 中文 (中国)
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Or troubleshoot an issue.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance
  • Account Team

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)
Red Hat Customer Portal Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • Runtimes

  • Integration and Automation

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus
  • Red Hat CodeReady Studio
  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycles

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem Catalog
  • Red Hat in the Public Cloud
  • Partner Resources

Tools

  • Solution Engine
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting

Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

  • Learn more
  • Go to Insights

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2012:0421 - Security Advisory
Issued:
2012-03-26
Updated:
2012-03-26

RHSA-2012:0421 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: rhevm security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated rhevm packages that fix one security issue and various bugs are now
available.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Description

Red Hat Enterprise Virtualization Manager is a visual tool for centrally
managing collections of virtual machines running Red Hat Enterprise Linux
and Microsoft Windows. These packages also include the Red Hat Enterprise
Virtualization Manager REST (Representational State Transfer) API, a set of
scriptable commands that give administrators the ability to perform queries
and operations on Red Hat Enterprise Virtualization Manager.

It was found that RESTEasy was vulnerable to XML External Entity (XXE)
attacks. If a remote attacker who is able to access the Red Hat Enterprise
Virtualization Manager REST API submitted a request containing an external
XML entity to a RESTEasy endpoint, the entity would be resolved, allowing
the attacker to read files accessible to the user running the application
server. This flaw affected DOM (Document Object Model) Document and JAXB
(Java Architecture for XML Binding) input. (CVE-2012-0818)

This update also fixes the following bugs:

  • Previously the REST API was ignoring the "Accept" header. This made it
    impossible to retrieve detailed information about specific sub-collections,
    including hosts and disks. The REST API has been updated and now processes
    the "Accept" header as originally intended. (BZ#771369)
  • The "start_time" Virtual Machine property was previously always set. This
    meant that even Virtual Machines that were stopped, had a value for
    "start_time". An update has been made to ensure that the "start_time"
    property is only set when the Virtual Machine has been started, and is
    running. (BZ#772975)
  • The 'rhevm-setup' script previously only ran successfully on systems with
    their locale set to 'en_US.UTF-8', 'en_US.utf-8', or 'en_US.utf8'. The
    script has since been updated to also run successfully in additional
    locales, including 'ja_JP.UTF-8'. (BZ#784860)
  • The REST API did not previously validate that all required parameters
    were provided when enabling power management. The response code returned
    would also incorrectly indicate the operation had succeeded where
    mandatory parameters were not supplied. An update has been made to ensure
    that the power management parameters are validated correctly. (BZ#785744)
  • Previously no warning or error was issued when the amount of free disk
    space on a host was low. When no free disk space remained on the host it
    would become non-responsive with no prior warning. An update has been made
    to report a warning in the audit log when a host's free disk space is less
    than 1000 MB, and an error when a host's free disk space is less than 500
    MB. (BZ#786132)
  • When importing Virtual Machines no notification was provided if the MAC
    address of the network interface card clashed with that of an existing
    Virtual Machine. Now when this occurs a message is printed to the audit
    log, highlighting the need for manual intervention. (BZ#795416)
  • Previously it was not possible to set more, or less, than one value for
    SpiceSecureChannels using the rhevm-config tool. This meant it was not
    possible to encrypt all SPICE channels. The rhevm-config tool has been
    updated and it is now possible to encrypt all SPICE channels, by adding
    them to the SpiceSecureChannels configuration key. (BZ#784012)

All Red Hat Enterprise Virtualization users are advised to upgrade to these
updated packages, which address this vulnerability and fix these bugs.
Refer to the Solution section for information about installing this update.

Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Follow the upgrade
procedure in the Red Hat Enterprise Virtualization
Installation Guide to install these updated packages:

http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Virtualization/3.0/html/Installation_Guide/chap-Installation_Guide-Installing_the_RHEV_Manager-Upgrades.html

Affected Products

  • Red Hat Virtualization 3 for RHEL 6 x86_64

Fixes

  • BZ - 785631 - CVE-2012-0818 RESTEasy: XML eXternal Entity (XXE) flaw

CVEs

  • CVE-2012-0818
  • CVE-2011-5245

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Virtualization/3.0/html/Installation_Guide/chap-Installation_Guide-Installing_the_RHEV_Manager-Upgrades.html
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Virtualization 3 for RHEL 6

SRPM
rhevm-3.0.3_0001-3.el6.src.rpm SHA-256: 80d89f868146049d11c1cbfb92e65dc39e3d9dda73f33f699c8b7c5357539e32
x86_64
rhevm-3.0.3_0001-3.el6.x86_64.rpm SHA-256: a8b1cb19f4bd2d673d0133e4330cdfb6c80edd40c13c110e6d388f711460cce3
rhevm-backend-3.0.3_0001-3.el6.x86_64.rpm SHA-256: f43e4f11c237000ff7186f63605685a4e10d95d09d4e8a16423ff1c94b2f3103
rhevm-config-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 0ea2b3ebc6d8bced94b1c16765fc34417d18ebcf45cb43edde9564d52d2776ca
rhevm-dbscripts-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 3300a3a000308d4155de45df0cd7e5b2872898c671d8b6275f974bead3888673
rhevm-debuginfo-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 3953b8d4ac30ad3e54076f2f380fb731ea337da49a9281a87615b8bc847a37a5
rhevm-genericapi-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 89b4c8e8c2c8908a32d7e09ab0c8296e9f105d1d5e7fff683a6c8f77b715fcc5
rhevm-iso-uploader-3.0.3_0001-3.el6.x86_64.rpm SHA-256: ed12ecd5c485437a824e5216b7f0cff20306ca8afdd0628f9eeda681e92f4baf
rhevm-jboss-deps-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 67e858d3f443deab1b02f03c54420eda604b0ce9f24d06e6cd13cef46809bc54
rhevm-log-collector-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 553a3bef9bb9e282deb5e18597f7420ccd0a84ad40a1c684c46b4d6dd547f43c
rhevm-notification-service-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 2a6d79458f33f3ff142f5a3a2d50671a59538acd6e2238f92d698bb9a5a839bd
rhevm-restapi-3.0.3_0001-3.el6.x86_64.rpm SHA-256: ba9b1164305d32d692709aa357753b4bbaef1ba13ed5b1641943b948aac48f39
rhevm-setup-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 1c6f642d6f33659a45e5421e673a304ee03d75f55c0259fd067229d7c84dbbfd
rhevm-tools-common-3.0.3_0001-3.el6.x86_64.rpm SHA-256: a555493cbf0ff021dbd8b310e32f095c1fed256fd9f81c276536fcfb486680cc
rhevm-userportal-3.0.3_0001-3.el6.x86_64.rpm SHA-256: 2fe7a610383e03a3d77a0c42dba40c723e0d2b13faee0ab8d5ea00d245e18b50
rhevm-webadmin-portal-3.0.3_0001-3.el6.x86_64.rpm SHA-256: db245d775d0fd901682c7d780eb424c52a0328e567d129d3bbaa938c627dbc31

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • openshift.com
  • developers.redhat.com
  • connect.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2021 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter Facebook