Red Hat JBoss Web Server 5.0 Service Pack 3 Release Notes

Red Hat JBoss Web Server 5.0

For Use with the Red Hat JBoss Web Server 5.0

Red Hat Customer Content Services

Abstract

These release notes contain important information related to the Red Hat JBoss Web Server 5.0 Service Pack 3.

Chapter 1. RedHat JBoss Web Server 5.0 Service Pack 3

Welcome to the Red Hat JBoss Web Server version 5.0 Service Pack 3 release. This purpose of this release is to cover Cloud Enablement security issues impacting JWS 5.0.

The JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It consists of:

  • Apache Tomcat: a servlet container in accordance with the Java Servlet Specification. JBoss Web Server contains Apache Tomcat 9.
  • The Apache Tomcat Native Library: a Tomcat library, which improves Tomcat scalability, performance, and integration with native server technologies.
  • The tomcat-vault extension: an extension for the JBoss Web Server used for securely storing passwords and other sensitive information used by a JBoss Web Server.
  • The mod_cluster library: a library that allows communication between Apache Tomcat and the Apache HTTP Server’s mod_proxy_cluster module. This allows the Apache HTTP Server to be used as a load balancer for JBoss Web Server.

Service packs for Red Hat JBoss Web Server are produced when a set of critical bug fixes and/or security patches are required before a new full release.

These service pack releases reduce the number of individual patches that we produce and enable customers to keep up to date.

This update includes all fixes and changes from Red Hat JBoss Web Server 5.0 Service Pack 2.

Note

From Red Hat JBoss Web Server 5.0 Service Pack 3, all the configuration files that were changed in the patch are appended by the suffix .zipnew to avoid overwriting existing configuration files.

If the new or changed properties or configuration options are applicable to you, you will need to manually add or define them in their respective property or configuration file.

Chapter 2. Installing the Red Hat JBoss Web Server 5.0

The JBoss Web Server 5.0 can be installed using one of the following sections of the installation guide:

Chapter 3. Upgrading Red Hat JBoss Web Server using this Service Pack

To install this service pack:

  1. Download the Red Hat JBoss Web Server 5.0 Service Pack 3 file (.zip format) appropriate to your platform using the download link here (subscription required).
  2. Extract the .zip file to the Red Hat JBoss Web Server installation directory.

For Red Hat Enterprise Linux users who have installed Red Hat JBoss Web Server from RPM packages, can upgrade to the latest service pack using yum:

# yum upgrade

Chapter 4. OS/JVM Certifications

There are no new certifications for this release.

Chapter 5. Security Fixes

This update includes fixes for the following security related issues:

IDImpactSummary

CVE-2019-10160

Important

python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc

CVE-2019-12735

Important

vim/neovim: ':source!' command allows arbitrary command execution via modelines

Chapter 6. Resolved issues

The following issues have been resolved in this release:

IssueDescription

JWS-1397

jboss-webserver*-jdk8-openshift-rhel* sometimes hangs at startup [Jolokia]

JWS-1420

Tomcat frequently hangs at startup when Jolokia loads certificate [jws-5.0.3]

Cloud-3262

[JWS50] Update mongodb driver to mongodb36

Cloud-3276

[JWS50] Important - python CVE-2019-10160

Cloud-3283

[JWS50] Important - vim CVE-2019-12735

Chapter 7. Known issues

See the JBoss Developer bug tracking software for a list of the Known issues for Red Hat JBoss Web Server 5.0 Service Pack 3.

Chapter 8. Upgraded components

There are no new upgraded components for this release.

Legal Notice

Copyright © 2019 Red Hat, Inc.
The text of and illustrations in this document are licensed by Red Hat under a Creative Commons Attribution–Share Alike 3.0 Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is available at http://creativecommons.org/licenses/by-sa/3.0/. In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shadowman logo, the Red Hat logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other countries.
Node.js® is an official trademark of Joyent. Red Hat is not formally related to or endorsed by the official Joyent Node.js open source or commercial project.
The OpenStack® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.
All other trademarks are the property of their respective owners.