JBoss Enterprise Application Platform 7.0 Update 02 Release Notes

Updated

In order to better meet customer expectations, micro releases for JBoss EAP 7 have been discontinued and replaced with updates delivered on a repeating schedule, targeting a new release every 6 weeks.

Each new update will contain a number of bug fixes for customer reported issues and potentially a number of security fixes. We expect that the updates will substantially reduce the number of individual patches that we produce and that customers must manage to keep their installations up to date.

For more information see the following Red Hat Knowledgebase articles: Maintenance Release Changes in EAP 6.2+ and Updated Patch Management with EAP 6.2+

This update includes all fixes and changes from This content is not included.JBoss EAP 7.0 Update 01

This update includes fixes for the following security related issues:

IDComponentSummary
CVE-2016-5406Domain ManagementRBAC configurations are discarded by transformers for legacy slaves running management API versions 1.8 and earlier
CVE-2016-4993Web (Undertow)HTTP header injection / response splitting
CVE-2015-0254XML FrameworksXXE and RCE via XSL extension in JSTL XML tags

This update includes the following bug fixes or changes:
IDComponentSummary
Content from issues.jboss.org is not included.JBEAP-4742ActiveMQDuplicate messages in replicated HA topology when backup is shutdowned
Content from issues.jboss.org is not included.JBEAP-5175ActiveMQFix bridge support for large messages
Content from issues.jboss.org is not included.JBEAP-4721ActiveMQIn rare circumstances MessageProducer can send a message to wrong queue.
Content from issues.jboss.org is not included.JBEAP-3419ActiveMQLost large messages if backup is shutdown during synchronization
Content from issues.jboss.org is not included.JBEAP-3313ActiveMQLost message when using transaction session on subscriber/consumer.
Content from issues.jboss.org is not included.JBEAP-3002ActiveMQNPE when suspending server with MDB deployed
Content from issues.jboss.org is not included.JBEAP-3675ActiveMQRedistribution loses large messages when server with HA is restarted
Content from issues.jboss.org is not included.JBEAP-4909ActiveMQmax-saved-replicated-journal-size is ignored
Content from issues.jboss.org is not included.JBEAP-5164ActiveMQServer should always remove old files beyond getMaxSavedReplicatedJournalsSize
Content from issues.jboss.org is not included.JBEAP-4862BatchAdd step property (jberet.analyzer.txDisabled) to allow applictions to turn off PartitionAnalyzer transactions
Content from issues.jboss.org is not included.JBEAP-4811BatchBatch thread tx context not cleaned up properly on tx timeout in chunk-type step
Content from issues.jboss.org is not included.JBEAP-4847BatchNPE in retry after a partitioned chunk
Content from issues.jboss.org is not included.JBEAP-3409BatchWhen a job listener is not found and the batch fails to start, we cannot detect the error using Batch API.
Content from issues.jboss.org is not included.JBEAP-4955CLIIn domain it is not possible to configure journal paths via CLI
Content from issues.jboss.org is not included.JBEAP-3969ClusteringSession draining always takes maximum configured timeout
Content from issues.jboss.org is not included.JBEAP-4665ClusteringJGRP-2045 - Can't init JChannel using FILE_PING when JVM is shutting down
Content from issues.jboss.org is not included.JBEAP-4664ClusteringJGRP-2051 - S3_PING.generatePreSignedUrl() has to use https for the protocol
Content from issues.jboss.org is not included.JBEAP-4670ClusteringJGRP-2058 - Probe: add bundler type at runtime
Content from issues.jboss.org is not included.JBEAP-4667ClusteringJGRP-2059 - Added AverageMinMax - UPerf now also shows RTT times
Content from issues.jboss.org is not included.JBEAP-5227ClusteringRPCs to non-existant FORK channel are dropped
Content from issues.jboss.org is not included.JBEAP-4984Domain ManagementInvalid unmanaged deployment breaks working managed deployments
Content from issues.jboss.org is not included.JBEAP-4273Domain Managementserver instances cannot find keytab during domain startup
Content from issues.jboss.org is not included.JBEAP-4594EEEJB with AroundConstruct interceptor with Object return type fails to deploy
Content from issues.jboss.org is not included.JBEAP-4682EJBEJB view service allows invocations through before component has started resulting in potential race
Content from issues.jboss.org is not included.JBEAP-3459RESTLog warning message if two end-points are conflicting on the same path
Content from issues.jboss.org is not included.JBEAP-4247SecurityAdvancedLdapLoginModule with rolesCtxDN=null leads to authentication failure
Content from issues.jboss.org is not included.JBEAP-4733SecurityFlagging of invalid login credential for datasource is inconsistent - JBossSecuritySubjectFactory should check the root cause exception
Content from issues.jboss.org is not included.JBEAP-5269SecurityPicketlink does not return SessionIndex in LogoutRequest
Content from issues.jboss.org is not included.JBEAP-3013SecurityRolesSearch in AdvancedLdapLoginModule is doing a needless LDAP call for each individual role
Content from issues.jboss.org is not included.JBEAP-4266SecurityAdvancedLdapLoginModule with rolesCtxDN="" can lead to authentication failure
Content from issues.jboss.org is not included.JBEAP-4216SecurityNullPointerException in DeploymentRoleToRolesMappingProvider
Content from issues.jboss.org is not included.JBEAP-4045SecuritySAML2STSLoginModule does not allow for configuring the ClockSkew
Content from issues.jboss.org is not included.JBEAP-2817SecurityThe root cause of login module failures gets lost when multiple login modules are stacked
Content from issues.jboss.org is not included.JBEAP-2491ServerWFCORE-761 - Not possible to overlay non existing file in WAR
Content from issues.jboss.org is not included.JBEAP-4748Web (Undertow)Add log message indicating disabled flag from web-fragments
Content from issues.jboss.org is not included.JBEAP-4927Web (Undertow)Provide username in trace logging for sec constraint during logout
Content from issues.jboss.org is not included.JBEAP-4821Web (Undertow)access log states incorrect sizes for gzipped resources
Content from issues.jboss.org is not included.JBEAP-5002Web ConsoleButtons at the end of modal panels get cut off
Content from issues.jboss.org is not included.JBEAP-4956Web ConsoleImpossible to read/configure messaging provider journal directory path
Content from issues.jboss.org is not included.JBEAP-5528Web ServicesCXFHandlerResolverImpl not threadsafe
Content from issues.jboss.org is not included.JBEAP-5523Web ServicesCoverity reports possible need to use doPrivileged block for MapToBeanConverter
Content from issues.jboss.org is not included.JBEAP-5527Web ServicesImprove isolation between integration code and user code
Content from issues.jboss.org is not included.JBEAP-5520Web ServicesPrevent Apache CXF from using ASM from user deployments
Content from issues.jboss.org is not included.JBEAP-5449Web ServicesSelf assignment of field WebserviceDescriptionMetaData.webservices
Content from issues.jboss.org is not included.JBEAP-5441Web ServicesWS-Discovery doesn't work in IPv6-only network
Content from issues.jboss.org is not included.JBEAP-4726Web Servicesjbossws-common - usage of Exception.printStackTrace() instead of logging feature
Content from issues.jboss.org is not included.JBEAP-4717Web Servicesjbossws-cxf - usage of Exception.printStackTrace() instead of logging feature
Content from issues.jboss.org is not included.JBEAP-3279Web Servicesslf4j is used by ws security related bits, logging bridge probably needed
Content from issues.jboss.org is not included.JBEAP-5521Web Serviceswsdl diretory is not cleaned on application deploy/undeploy thereby leaving an empty folder under "/wsdl/data" directory
Content from issues.jboss.org is not included.JBEAP-3711Web ServicesCXF-6799 - java.lang.ClassCastException: sun.reflect.generics.reflectiveObjects.ParameterizedTypeImpl cannot be cast to java.lang.reflect.TypeVariable
Content from issues.jboss.org is not included.JBEAP-5232XML FrameworksFix regression - JSTL TransformSupport XSL import not finding relative path
Content from issues.jboss.org is not included.JBEAP-4913XML FrameworksAfter upgrading some of the attributes are not resolved by x:transform

Note: This update should only be applied to installer or zip-based installations.

To apply this update using the CLI on Unix-based systems, run the following command from JBOSS_HOME:

bin/jboss-cli.sh "patch apply path/to/jboss-eap-7.0.2-patch.zip"

To apply this update using the CLI on Windows-based systems, run the following command from JBOSS_HOME:

bin\jboss-cli.bat "patch apply path\to\jboss-eap-7.0.2-patch.zip"

These commands will apply the update to the installation that contains the CLI script. Other scenarios and use of the management console are covered in the This content is not included.JBoss EAP 7.0 Patching And Upgrading Guide

Category
Components
Article Type