Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2020:0861 - Security Advisory
Issued:
2020-03-17
Updated:
2020-03-17

RHSA-2020:0861 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Web Server 3.1 Service Pack 8 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and RHEL 7.

Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache HTTP Server, the Apache Tomcat Servlet container, Apache Tomcat Connector (mod_jk), JBoss HTTP Connector (mod_cluster), Hibernate, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 3.1 Service Pack 8 serves as a replacement for Red Hat JBoss Web Server 3.1, and includes bug fixes, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • tomcat: session fixation (CVE-2019-17563)
  • tomcat: local privilege escalation (CVE-2019-12418)
  • tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability (CVE-2020-1938)
  • tomcat: XSS in SSI printenv (CVE-2019-0221)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files).

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 3 for RHEL 7 x86_64
  • JBoss Enterprise Web Server 3 for RHEL 6 x86_64
  • JBoss Enterprise Web Server 3 for RHEL 6 i386

Fixes

  • BZ - 1713275 - CVE-2019-0221 tomcat: XSS in SSI printenv
  • BZ - 1785699 - CVE-2019-12418 tomcat: local privilege escalation
  • BZ - 1785711 - CVE-2019-17563 tomcat: session fixation when using FORM authentication
  • BZ - 1806398 - CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability

CVEs

  • CVE-2019-0221
  • CVE-2019-12418
  • CVE-2019-17563
  • CVE-2020-1938

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/html/3.1.0_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 3 for RHEL 7

SRPM
tomcat-native-1.2.23-21.redhat_21.ep7.el7.src.rpm SHA-256: 791a9fd82540723699429c2851aee4db024c6e7e91947a9ac404789765a7160b
tomcat7-7.0.70-38.ep7.el7.src.rpm SHA-256: 7cdb1a2f700a91d82829b4fa4048adecbeac5ad7a29eba991bcf41ea88f97690
tomcat8-8.0.36-42.ep7.el7.src.rpm SHA-256: 55068c806b4013f570afe24b12f3ab1e4a1535a5e1aaaa228422f2c1a1773712
x86_64
tomcat-native-1.2.23-21.redhat_21.ep7.el7.x86_64.rpm SHA-256: 308cf609ee10a19e3090e126e912adad6abb04c0ae68e922538ab73a55e0194e
tomcat-native-debuginfo-1.2.23-21.redhat_21.ep7.el7.x86_64.rpm SHA-256: d16a91537fe282933fde0d1fb47325ed82a2f915f1741c25037c196903fe8689
tomcat7-7.0.70-38.ep7.el7.noarch.rpm SHA-256: e19db7256fade127d66669f4f74b7aa907de0a85fba2b67a4df2e50222d82538
tomcat7-admin-webapps-7.0.70-38.ep7.el7.noarch.rpm SHA-256: a89c5c4775e02af31e6e39caaf0683f44a0ffa77cee04e60bb9c2b1e5c48b687
tomcat7-docs-webapp-7.0.70-38.ep7.el7.noarch.rpm SHA-256: ea20c051e8d19ec682e447359cf105c87ef11fc0fbc037bfc6e146ed86fdaac9
tomcat7-el-2.2-api-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 3ee7c6dab964973b1a280c6b6c52e761183d7038299ca159649972cebbeba4cf
tomcat7-javadoc-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 1803aba30162efb2a41d71f9683121766b49a3805596cc57ab3aaa4db26f3ddf
tomcat7-jsp-2.2-api-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 48525ae26a6d02d1a9852b887fbb4998a2f02c9e67e46832b15855dff822ddff
tomcat7-jsvc-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 3aec919b069789d9ac09122fc88a0acb7f453701b8ffef839dd7231c8445c237
tomcat7-lib-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 57d14c174a25bf89b5782c1a316ab57e7935fd5a7086f308df587478aec02a97
tomcat7-log4j-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 459f0c49a4606bc8d4c54dab1b9ae119fab04469deb8d5f345b0930d47cb09d3
tomcat7-selinux-7.0.70-38.ep7.el7.noarch.rpm SHA-256: b9e4b157e5d0b430a2f3b7629a2f48f5b74ee481199bbe243e496dcf79041e3d
tomcat7-servlet-3.0-api-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 1f66ac412383e50672f7a965e8d63af44361cda0ed860bc992dbfb757e18ddfa
tomcat7-webapps-7.0.70-38.ep7.el7.noarch.rpm SHA-256: 56999842755158260757f45ad8ae403baf1d7054d105985106d88ecd3035ea8b
tomcat8-8.0.36-42.ep7.el7.noarch.rpm SHA-256: a38a2f85cdcd440efb8f8f2eb9ccaebd6bfaaf461d8fd3d5eb695fa28646d882
tomcat8-admin-webapps-8.0.36-42.ep7.el7.noarch.rpm SHA-256: a8b3382bd88cd4d6bf1356c02e4c1403c9d6f0eb86d14009e118e4b6c5861378
tomcat8-docs-webapp-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 13127847b4c60fee6bf4bbf9ea116be723d5ba9cadffc11ca1ddb79dbcc040e4
tomcat8-el-2.2-api-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 0b2d0395724c2be960b681cd9aa3c72b385d59b86b32fc239998de443a9d8389
tomcat8-javadoc-8.0.36-42.ep7.el7.noarch.rpm SHA-256: da37400355ecc0d3a7f9258438e36b91351d2e6ab3a2b146b80354431322e241
tomcat8-jsp-2.3-api-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 8ea4942f496bcfe67e37acd0694877e2303f50ef05bfa9e704b0ff4bea63f1e7
tomcat8-jsvc-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 55bfe0ef9a77f4d46d229e600c358a17e9a485cf94c58f81aa27cef4084ae881
tomcat8-lib-8.0.36-42.ep7.el7.noarch.rpm SHA-256: acdce0da352bf6586e2e3447b51958b589a30b3edc88eb8523abc3bd91f4bc75
tomcat8-log4j-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 60b129916fbac3888d84d62b5c36ddc366f78d0616e106b33720d7cb7b68f70b
tomcat8-selinux-8.0.36-42.ep7.el7.noarch.rpm SHA-256: 3bf4e40e928eb55653f66d4bd7f121e8097495500105bef81fb03b0156ed5b2d
tomcat8-servlet-3.1-api-8.0.36-42.ep7.el7.noarch.rpm SHA-256: b61cde1bb1c45a41ac425c7f3867b6f90e60af723aa8420373af7a3095771210
tomcat8-webapps-8.0.36-42.ep7.el7.noarch.rpm SHA-256: d2f96da7a16a70954ebe99ff98280e4ea85c64bdfcd0c54be806d8a881934a49

JBoss Enterprise Web Server 3 for RHEL 6

SRPM
tomcat-native-1.2.23-21.redhat_21.ep7.el6.src.rpm SHA-256: 631d7c3761a9f2b3d38062ba0565d609493fcd7955510bbce3474b1d2da2386c
tomcat7-7.0.70-38.ep7.el6.src.rpm SHA-256: 4dc05264c8285a2283332e06d0aae779d4e2250e5916545bfe356757741fbb99
tomcat8-8.0.36-42.ep7.el6.src.rpm SHA-256: 9433b2239411f113f66d478ab7b6a520c5150268f2a579d12b3856e43a846cfe
x86_64
tomcat-native-1.2.23-21.redhat_21.ep7.el6.x86_64.rpm SHA-256: 50cd91be34c1f0e2e60ca3c5947720bc594c36fc34bb3c8cfbc451fb1398f2cb
tomcat-native-debuginfo-1.2.23-21.redhat_21.ep7.el6.x86_64.rpm SHA-256: a2e2e8c991dfb26164a55b88f54edb477dbd70b87061cf0f6473b329d26451f5
tomcat7-7.0.70-38.ep7.el6.noarch.rpm SHA-256: e23911ba8cc6c048dcc866b7f11b4c935cff04d175e45722fd186d20b3776088
tomcat7-admin-webapps-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 661e383c2ce3ad63e3f3398178f617ac9e96d455ba83a56af3b2572d2e8905ca
tomcat7-docs-webapp-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 6b800b6ec1c03f7407c6eb6641ca27de367733dc694577ef76e72179b28ab021
tomcat7-el-2.2-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 4414c574d985de0217b7cf81d52bef9fdb421d7944835137e14307552fd9e014
tomcat7-javadoc-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 5d7f4e0e31623db38d366747fcd1b538bf3346706d528d62ac53e68422ff8b90
tomcat7-jsp-2.2-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: dba1d98a89c229d382cb7de02e089ff55b1a194b0951e7f6ed87286c8cc66c9e
tomcat7-jsvc-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 6f893eaccfd0d69b0e074cc2626f52dd6b920df7de851fce2e72a08d1f19b0c2
tomcat7-lib-7.0.70-38.ep7.el6.noarch.rpm SHA-256: a2c212647db3d4553a8eed9c31a7b3da1b1cc677361499fef1fffe07b86d43eb
tomcat7-log4j-7.0.70-38.ep7.el6.noarch.rpm SHA-256: ff87b3704dd1f4045fbe5fb16225f0251c042a6a6d5dc302852a7ae6fc3a0f9e
tomcat7-selinux-7.0.70-38.ep7.el6.noarch.rpm SHA-256: af352f0763330b119bbf56db042b25aa494c1cb75bbc700007f9d1818befbc02
tomcat7-servlet-3.0-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 9eeb1f6e4fe3f2ce547a9a234492a901209875d4e80ab5b7ba6cd936b38021d7
tomcat7-webapps-7.0.70-38.ep7.el6.noarch.rpm SHA-256: ab8743fdbb8a251a76aeacf27cb1df2f0faf7b60d0541550a6e3af6b2402bd27
tomcat8-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 0af10c51ef68144c6b53a9cd8c0c94181d7601261dd726867885f5471001554b
tomcat8-admin-webapps-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b6d1ab6a6ae5104b0c62e386a15bfff8e85506fc817e68db9872a540947834ad
tomcat8-docs-webapp-8.0.36-42.ep7.el6.noarch.rpm SHA-256: ff6f26905a14217612aa974381b29084342e7305c69e0957a0c214937e4e062e
tomcat8-el-2.2-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: ead63284ca53316f9264d28c5b2376f106fc6b33fa870c28b32bca8f9a6a1b16
tomcat8-javadoc-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 39e7b24dca6107df2463c1e68f8de3d21a1853396faaac362823dd93a0d9b2ba
tomcat8-jsp-2.3-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 4a808bf71c39530e74a50200b10c26d61e565f6b40270a22664c2c4660893b5d
tomcat8-jsvc-8.0.36-42.ep7.el6.noarch.rpm SHA-256: db29cb37ae88319589ee29f6b288ddcea99285efa77a47c62e1a56aa6e2382e4
tomcat8-lib-8.0.36-42.ep7.el6.noarch.rpm SHA-256: bab5fb95ebfa68746ecbfe534476533300dd34ef313fc47420a87abc83330e37
tomcat8-log4j-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b2ba67016e7db500697ec708c8aa40c0b500b1e12d8fbe1a08e556c6f970b32b
tomcat8-selinux-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 17faff174b48dd0ab9954bfa09911d8247fab45733b301fc843859e49f81a782
tomcat8-servlet-3.1-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 93ae0360fdf842efa279f096ffc55176d4416169935021107f5c6a7dbce9df44
tomcat8-webapps-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b2fc72470f6c1160db2e2409f41dd1e6b37d7b4dccb791cb20d91efe6696b973
i386
tomcat-native-1.2.23-21.redhat_21.ep7.el6.i686.rpm SHA-256: 9aa2dd94976c3f370e962c43e0c9e1d65ab1083beba08271de4b3d732e47657b
tomcat-native-debuginfo-1.2.23-21.redhat_21.ep7.el6.i686.rpm SHA-256: f1f5ede18810fa43e324988e5b61738a8cf96cc001cd18376e8fd8c2f91d28cf
tomcat7-7.0.70-38.ep7.el6.noarch.rpm SHA-256: e23911ba8cc6c048dcc866b7f11b4c935cff04d175e45722fd186d20b3776088
tomcat7-admin-webapps-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 661e383c2ce3ad63e3f3398178f617ac9e96d455ba83a56af3b2572d2e8905ca
tomcat7-docs-webapp-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 6b800b6ec1c03f7407c6eb6641ca27de367733dc694577ef76e72179b28ab021
tomcat7-el-2.2-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 4414c574d985de0217b7cf81d52bef9fdb421d7944835137e14307552fd9e014
tomcat7-javadoc-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 5d7f4e0e31623db38d366747fcd1b538bf3346706d528d62ac53e68422ff8b90
tomcat7-jsp-2.2-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: dba1d98a89c229d382cb7de02e089ff55b1a194b0951e7f6ed87286c8cc66c9e
tomcat7-jsvc-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 6f893eaccfd0d69b0e074cc2626f52dd6b920df7de851fce2e72a08d1f19b0c2
tomcat7-lib-7.0.70-38.ep7.el6.noarch.rpm SHA-256: a2c212647db3d4553a8eed9c31a7b3da1b1cc677361499fef1fffe07b86d43eb
tomcat7-log4j-7.0.70-38.ep7.el6.noarch.rpm SHA-256: ff87b3704dd1f4045fbe5fb16225f0251c042a6a6d5dc302852a7ae6fc3a0f9e
tomcat7-selinux-7.0.70-38.ep7.el6.noarch.rpm SHA-256: af352f0763330b119bbf56db042b25aa494c1cb75bbc700007f9d1818befbc02
tomcat7-servlet-3.0-api-7.0.70-38.ep7.el6.noarch.rpm SHA-256: 9eeb1f6e4fe3f2ce547a9a234492a901209875d4e80ab5b7ba6cd936b38021d7
tomcat7-webapps-7.0.70-38.ep7.el6.noarch.rpm SHA-256: ab8743fdbb8a251a76aeacf27cb1df2f0faf7b60d0541550a6e3af6b2402bd27
tomcat8-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 0af10c51ef68144c6b53a9cd8c0c94181d7601261dd726867885f5471001554b
tomcat8-admin-webapps-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b6d1ab6a6ae5104b0c62e386a15bfff8e85506fc817e68db9872a540947834ad
tomcat8-docs-webapp-8.0.36-42.ep7.el6.noarch.rpm SHA-256: ff6f26905a14217612aa974381b29084342e7305c69e0957a0c214937e4e062e
tomcat8-el-2.2-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: ead63284ca53316f9264d28c5b2376f106fc6b33fa870c28b32bca8f9a6a1b16
tomcat8-javadoc-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 39e7b24dca6107df2463c1e68f8de3d21a1853396faaac362823dd93a0d9b2ba
tomcat8-jsp-2.3-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 4a808bf71c39530e74a50200b10c26d61e565f6b40270a22664c2c4660893b5d
tomcat8-jsvc-8.0.36-42.ep7.el6.noarch.rpm SHA-256: db29cb37ae88319589ee29f6b288ddcea99285efa77a47c62e1a56aa6e2382e4
tomcat8-lib-8.0.36-42.ep7.el6.noarch.rpm SHA-256: bab5fb95ebfa68746ecbfe534476533300dd34ef313fc47420a87abc83330e37
tomcat8-log4j-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b2ba67016e7db500697ec708c8aa40c0b500b1e12d8fbe1a08e556c6f970b32b
tomcat8-selinux-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 17faff174b48dd0ab9954bfa09911d8247fab45733b301fc843859e49f81a782
tomcat8-servlet-3.1-api-8.0.36-42.ep7.el6.noarch.rpm SHA-256: 93ae0360fdf842efa279f096ffc55176d4416169935021107f5c6a7dbce9df44
tomcat8-webapps-8.0.36-42.ep7.el6.noarch.rpm SHA-256: b2fc72470f6c1160db2e2409f41dd1e6b37d7b4dccb791cb20d91efe6696b973

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility