Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHEA-2025:19729 - Product Enhancement Advisory
Issued:
2025-11-04
Updated:
2025-11-04

RHEA-2025:19729 - Product Enhancement Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat 3scale API Management 2.16.0 Release - Container Images

Type/Severity

Product Enhancement Advisory

Topic

Red Hat 3scale API Management 2.16.0 Release - Container Images

Description

Release of 3scale API Management components provides these changes:

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.14/html-single/installing_3scale/index

Affected Products

  • Red Hat 3scale API Management Platform 2 for RHEL 8 x86_64
  • Red Hat 3scale API Management Platform 2 for RHEL 8 s390x
  • Red Hat 3scale API Management Platform 2 for RHEL 8 ppc64le
  • Red Hat 3scale API Management Platform 2 for RHEL 7 x86_64
  • Red Hat 3scale API Management Platform 2 for RHEL 7 s390x
  • Red Hat 3scale API Management Platform 2 for RHEL 7 ppc64le

Fixes

  • THREESCALE-11020 - Add a way for the user to provide Redis TLS certs and keys for porta and backend
  • THREESCALE-11021 - Add a way for the client to provide redis ACL credentials to system and backend
  • THREESCALE-11457 - system-searchd pod crashing on s390x
  • THREESCALE-8404 - TLS and ACL support for Redis connection
  • THREESCALE-10018 - ActiveDocs shows Error when a response body is CSV and starts from double quote
  • THREESCALE-10180 - Upgrade to sidekiq 7
  • THREESCALE-10233 - Support OAS 3.1 in System Active Docs
  • THREESCALE-10588 - CMS should not be marked as TP
  • THREESCALE-10761 - Problem with special chars in application_id in utilization
  • THREESCALE-10763 - Application description can not be {NUMBER}_
  • THREESCALE-10843 - Add more detailed session and account activity to Audit Logs
  • THREESCALE-10880 - Upgrade porta to Rails 6.1
  • THREESCALE-10924 - keep only a single set of porta configuration files
  • THREESCALE-11076 - Sidekiq: Extract the `:ssl` param from the Redis URL
  • THREESCALE-11090 - No description in [Product_applications_listing]
  • THREESCALE-11179 - Account Settings > Users > SSO Integrations (Empty view)
  • THREESCALE-11198 - Upgrade to sidekiq 7.3
  • THREESCALE-11205 - Accept sentinels credentials in the redis URI
  • THREESCALE-11214 - Provider creation via API sometimes fails because of tenant ID check
  • THREESCALE-11276 - Disapearing item from the accounts new field definition dropdown menu
  • THREESCALE-11378 - Incorrect message in Access Code input form
  • THREESCALE-11494 - Prepare 3scale-operator master branch for 2.16
  • THREESCALE-11499 - 3scale accounts listing can't filter by state
  • THREESCALE-11536 - Backend: Get rid of `rspec_api_documentation` gem
  • THREESCALE-2689 - Add the ability to create or update a Service Subscription using the 3scale API
  • THREESCALE-7340 - Upgrade to webpack@5
  • THREESCALE-7955 - User model extra fields not updating via admin portal form
  • THREESCALE-8038 - System-app postgreSQL libraries does not support scram-sha-256 for passwords
  • THREESCALE-8102 - Make route creation in zync optional.
  • THREESCALE-8271 - 3scale is not capable to have 2 different Applications with the same clientID, even in different RH-SSO Realms: it doesn't store the secrets accordingly
  • THREESCALE-8319 - The 3scale API endpoint /admin/api/settings.json doesn't update account_approval_required field
  • THREESCALE-8735 - Client secret in clear text in the API Manager UI (RH SSO Integration)
  • THREESCALE-8770 - Invoice line items with negative cost can't be created from the UI
  • THREESCALE-9033 - Some special characters in Application Keys are not supported
  • THREESCALE-9169 - Upgrade porta to ruby 3.1
  • THREESCALE-9596 - Update Sidekiq
  • THREESCALE-9682 - Backend Opentelemetry instrumentation
  • THREESCALE-9780 - ActiveDocs table
  • THREESCALE-9784 - PF4 table toolbar
  • THREESCALE-9896 - Implement EmptyState
  • THREESCALE-10156 - Make ssl_verify_client directive configurable
  • THREESCALE-10894 - Multiple filter service warnings are logged when APICAST_SERVICES_LIST is used.
  • THREESCALE-11015 - Introspection Policy does not work when `fapi-1-baseline` client policy is enabled in RHKB
  • THREESCALE-11036 - Investigate path routing + TLS termination policy
  • THREESCALE-11194 - APIcast using stale configuration for a deleted Product
  • THREESCALE-6454 - APIcast connections should be drained gracefully on pod deletion
  • THREESCALE-8149 - Enable to configure the Upstream Connection timeouts globally
  • THREESCALE-9301 - fix dns cache miss
  • THREESCALE-9320 - Conditional policy evaluating incorrectly: second policy in policy chain always triggers
  • THREESCALE-10601 - Bump OpenResty from 1.19 to 1.21
  • THREESCALE-11770 - Incorrect 3scale version in UI 2.16.0RC1
  • THREESCALE-11771 - Apicast pods failing on ppc64l
  • THREESCALE-11796 - Options in FAPI policy cannot be set.
  • THREESCALE-11757 - fix local dev make cluster/create/system-mysql
  • THREESCALE-11850 - Preflight check fails on redis-sentinel
  • THREESCALE-11868 - Remove mysql and redis image reference from csv and build
  • THREESCALE-11805 - system-app-pre/post hook always trigger
  • THREESCALE-11951 - operator reverts payment customatization suggested by documentation
  • THREESCALE-12002 - PSQL15 cause error system pre hook failed on FIPS enabled cluster
  • THREESCALE-11554 - 3scale operator fails to reconcile a Product CR when a backend reference is removed from usages and application plan limit is removed too
  • THREESCALE-11897 - Add support for PostgreSQL 15
  • THREESCALE-11619 - Support PostgreSQL 15 in System and Zync
  • THREESCALE-11610 - Apicast policies fail to validate
  • THREESCALE-12040 - Block 2.16 upgrade if 3scale is run with oracle DB

CVEs

  • CVE-2025-6395
  • CVE-2025-32988
  • CVE-2025-32989
  • CVE-2025-32990

References

(none)

aarch64

3scale-amp2/3scale-apicast-operator-bundle@sha256:d3738043b2d8b4ac99f054ee8ae3d7566c350024a1b1b832eb7d648ec95c21e9
3scale-amp2/apicast-gateway-rhel8@sha256:a3e06779eccce8407cd5f0dab60a6972096f3c141ff823beeb7c2e582aefeefe
3scale-amp2/apicast-rhel9-operator@sha256:fde4bce438a9b2f366249e70ff161fdb00cc88a4fdbc041c21ed784689da0a5b

ppc64le

3scale-amp2/3scale-apicast-operator-bundle@sha256:40d14ec73f34ad555a6e1cf9406b7a8359c67e8c86b57f4ea59cf35ee995f2fd
3scale-amp2/3scale-auth-wasm-rhel8@sha256:21000a89f44c3e40f78566a4779540d751112d4c5e897c511c4ca667ce20d1bf
3scale-amp2/3scale-operator-bundle@sha256:fd50b7c4c8103edb8d5da7565238122589d8a6f1d932cbe9125b512d70b90f62
3scale-amp2/3scale-rhel9-operator@sha256:e424c7e29e4f75621e8d0f1d61f99fb38a84323379f8dcaf9d83d908c0c3326d
3scale-amp2/apicast-gateway-rhel8@sha256:5ec661435d9bd550f9da355a220dae847ee2c366958a5264a892c7bc754385f2
3scale-amp2/apicast-rhel9-operator@sha256:2833ed380d7e57e0f8b749f938449694864972c862f4f02bf176778559f531ce
3scale-amp2/backend-rhel8@sha256:59ed00df07b0f1ab935d5e1db8be09395e45d6433764e9e9497dd7bba2ef4aba
3scale-amp2/manticore-rhel9@sha256:69211c2541b4f1a664207dfdf5ac272a5aa1ff9d588736ca0c976ae95e5fc09a
3scale-amp2/system-rhel9@sha256:e1ccf002920d8de7a4e46d8e425afd25eaaa4d1ebced198fb9dc1a1d64df2617
3scale-amp2/toolbox-rhel9@sha256:07437a5e14b9ae0ed702b94e390cca7272bb5757b560b76fea4da714398c046e
3scale-amp2/zync-rhel9@sha256:8ab69c423ca57cede70652356ed9403098fd62e9465ee1cc03eb78b3b5e0df0b

s390x

3scale-amp2/3scale-apicast-operator-bundle@sha256:6f5f39f596182bda431759576415b7f123576cedf212df14daa1c5fe2ec98d1e
3scale-amp2/3scale-auth-wasm-rhel8@sha256:d431fc5ca6fcb9a55b3fa4c89bc515f0819b74bd3d277bc48fe3999db47fd958
3scale-amp2/3scale-operator-bundle@sha256:b055f76a793d092a90553472d281e4c3593253368e3250721bc3750e3ecdf942
3scale-amp2/3scale-rhel9-operator@sha256:71fe638559c2da83a6864dd24dfbff81baf50758e4b175edd8de9035b7540d54
3scale-amp2/apicast-gateway-rhel8@sha256:1c984c9c843296ac6b30b06243867693fd9f6d193fa1af7e9b1b9a508114192e
3scale-amp2/apicast-rhel9-operator@sha256:db86f2ae673c694b674ed92b48a820e472e95e3445ed41a2a96b0cedccd4bf3e
3scale-amp2/backend-rhel8@sha256:c3030db3bc9e467627866d20ff685ee31875c10fa034d6afe8cc9087d747dfec
3scale-amp2/manticore-rhel9@sha256:cfc158d1ec8f51bf41496b0150917195a7c8399d20f14004b84621943e554059
3scale-amp2/system-rhel9@sha256:859a33a7f7c3695fa0dce15968ede573b0e13e127dc880892ad0eb6ef2471fe3
3scale-amp2/toolbox-rhel9@sha256:9c250efa3a3cd36e357079bfd871328ffec6f94bcea0acf4378e12e8f274e7a9
3scale-amp2/zync-rhel9@sha256:4902db22f6bb7ece1c5be293d91b7159b79c61e88477cd710ada4d33d8939000

x86_64

3scale-amp2/3scale-apicast-operator-bundle@sha256:eee3bcda197fa12d241b24dc0196757f7181f059268bb6aef19ffce055fa5f93
3scale-amp2/3scale-auth-wasm-rhel8@sha256:9936d444c7e4bc72b09920c1ff8ced29da32e64f7fe0e60d15d445156b1042e1
3scale-amp2/3scale-operator-bundle@sha256:7fb3cf02e3753ff3696f8feaad3ec2b12f9477dc4f0113bd9022694fdf5c6992
3scale-amp2/3scale-rhel9-operator@sha256:6576ac9ac0e87e1d253a4507f7df808fef345fa8fe6e756eb4cf0730135b1e64
3scale-amp2/apicast-gateway-rhel8@sha256:a39065ffa0ff722ad45011b17ee301b8ec3bf7b139e52e30a81e08833f3ba4ea
3scale-amp2/apicast-rhel9-operator@sha256:fbe7623c05644a5cbe476ed120998b1d49f4e26135fa37621adad30c4352c916
3scale-amp2/backend-rhel8@sha256:1d4e3b027d16e2f43987aa2efb078a192aeb50bc16f5339b87c2657c1ef61338
3scale-amp2/manticore-rhel9@sha256:bf4dd610834c479a022c374642193f8822a1157ae63ba905f6355c510efbb060
3scale-amp2/system-rhel9@sha256:c53cf7f3590ee17b43608e632e8891d3b7f45ae5b01837352c9bcdc0bac04c9b
3scale-amp2/toolbox-rhel9@sha256:ed7dad1a64b876a5262f3d596a1d0c0671c6a28113842493a70ef5bf9b4391e4
3scale-amp2/zync-rhel9@sha256:17a5b64801c6ba910af81f0e2b4458e38f53731570cbe92a5a75d6504ade80e9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility