Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0342 - Security Advisory
Issued:
2025-01-21
Updated:
2025-01-21

RHSA-2025:0342 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Web Server 6.0.5 release and security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Web Server 6.0 on Red Hat Enterprise Linux versions 8 and 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 6.0.5 serves as a replacement for Red Hat JBoss Web Server 6.0.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat: RCE due to TOCTOU issue in JSP compilation [jws-6] (CVE-2024-50379)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 6 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 8 x86_64

Fixes

  • BZ - 2332817 - CVE-2024-50379 tomcat: RCE due to TOCTOU issue in JSP compilation

CVEs

  • CVE-2024-50379

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.0/html-single/red_hat_jboss_web_server_6.0_service_pack_5_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 6 for RHEL 9

SRPM
jws6-tomcat-10.1.8-15.redhat_00022.1.el9jws.src.rpm SHA-256: babd0524c76781daeabf5e194f0ee313ea0549101a12eb1c585aafeb252dd00a
x86_64
jws6-tomcat-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: f222075210ac52a71bb91d6f7ea338833a1d938d6d8b12fe3aee07baa4727d1c
jws6-tomcat-admin-webapps-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 32d12c4a8facbc8c65d9fde9399a7f7592f33c334a387f0d0349d547d5f249d6
jws6-tomcat-docs-webapp-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: dc3e8107ba7373e7c5a811ab953de0c46a72efe9acaac3565bc63e68d6e62076
jws6-tomcat-el-5.0-api-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 963d977fd8993d7d5e57f30db9477230579a0a8ed81306b01e2ee94289f86071
jws6-tomcat-javadoc-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 906efb8c7862136435c010d3398f59633a30da6e967d65e3e8ea5fcd1d4166b2
jws6-tomcat-jsp-3.1-api-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: c2dd6b432c2166f11c6dc0133e7a420bd92ccb9b8b06739638144771cee49f39
jws6-tomcat-lib-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 400900c97351f73fef8feb8289574d4a1b45c8067f66c70b6697b65dcea0c716
jws6-tomcat-selinux-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: ab0ea2cd0d1ce0ef45834c4ed8a4b897fd6655d6e223bc649bb4374c33c02e5d
jws6-tomcat-servlet-6.0-api-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 8b643028a3be42a6838dc7bf5b08b3ecb173bfede542f1ffb85835aa3ec72bc9
jws6-tomcat-webapps-10.1.8-15.redhat_00022.1.el9jws.noarch.rpm SHA-256: 505c10c25c26b2c8fa449f6be6c24c6d76f5e9d92b8edb132783bd5173a8066c

JBoss Enterprise Web Server 6 for RHEL 8

SRPM
jws6-tomcat-10.1.8-15.redhat_00022.1.el8jws.src.rpm SHA-256: 857bf24f9e0f64de2e98c5c9ed4cb893163ac336eb94e7a6ffd9e574e13d7815
x86_64
jws6-tomcat-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: faf37d52fbe9180e72409f4b4c86148fe0abae4397e65ace2970a7ef71c12704
jws6-tomcat-admin-webapps-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: 386e3339cf5c3e5f7807a54eaae0367564102e98a61959271fd4b503ee60f4ef
jws6-tomcat-docs-webapp-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: bf01a150508f7ecef8466171319cc6507d6a9d9cdc8cc0acb0154f61d1b870d1
jws6-tomcat-el-5.0-api-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: c6b66b0d15c9121514d6e1e5547b2bc9a4e247bb8d07689bdf6212bed814e068
jws6-tomcat-javadoc-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: 74e109a45d4fcbd790e0bc89b94cf86d523f2011b0051d04bab0772036efcde6
jws6-tomcat-jsp-3.1-api-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: ca7806763fc0c61545a075534c174b50b607736dded359de87bfebbb3a9efebf
jws6-tomcat-lib-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: dbf57a92cda1b0f38f655ab6c4e5a9fd41a779da48afc7797e11aa8cc74606c2
jws6-tomcat-selinux-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: 729e71f873b05f3c7b8391d9a8a5c2ec49aecbb7e2998695c5d5aa10d434b1a0
jws6-tomcat-servlet-6.0-api-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: 5652601eef1983aca0a829e23a6540631abed8935aac7b0f00b4f9de85a2e2d5
jws6-tomcat-webapps-10.1.8-15.redhat_00022.1.el8jws.noarch.rpm SHA-256: 8d4ab1e25a862355df8229506042be7aa71494009cbfcbf3b10cbac91251ce6e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility