Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0361 - Security Advisory
Issued:
2025-01-16
Updated:
2025-01-16

RHSA-2025:0361 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Web Server 5.8.2 release and security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Web Server 5.8 on Red Hat Enterprise Linux versions 7, 8, and 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 5.8.2 serves as a replacement for Red Hat JBoss Web Server 5.8.1. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat: RCE due to TOCTOU issue in JSP compilation [jws-5] (CVE-2024-50379)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 5 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 8 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 7 x86_64

Fixes

  • BZ - 2332817 - CVE-2024-50379 tomcat: RCE due to TOCTOU issue in JSP compilation

CVEs

  • CVE-2024-50379

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/5.8/html-single/red_hat_jboss_web_server_5.8_service_pack_2_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 5 for RHEL 9

SRPM
jws5-tomcat-9.0.87-6.redhat_00006.1.el9jws.src.rpm SHA-256: 19c1c8bd498e27e11e550063bf49a2135b248f89b59659891839d48f5a46ae3f
x86_64
jws5-tomcat-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: 4aa81f887a45879810944e5c5a34f72046d706e225eb3a7d6f356fc2d19cf5f9
jws5-tomcat-admin-webapps-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: 6a8541d6bc44f3d367ffaf56bb2290a68866a94c60701368b9e351e27dd4fd84
jws5-tomcat-docs-webapp-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: dd0e80a8a6ea55237c23803cb5205c57e59eb78c1fe66bd1c7b0779a583a138e
jws5-tomcat-el-3.0-api-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: 563e31e447691ef6b78ac3ea524d52ca6f14ba3ee75264184ebb01120770faab
jws5-tomcat-javadoc-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: d0f023e9bb7ba10d0362b025818b6e1b31fb09b1fa57036b6c26b9450e31b027
jws5-tomcat-jsp-2.3-api-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: cd3a00a0cc7d0c65d30fc2f9daeb88b53f0fd78e9dce98797a5a060ca72cfa65
jws5-tomcat-lib-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: f421113143e5d0ac55873e55f8b597370dab8807c57733c7d79edf7b72a41858
jws5-tomcat-selinux-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: ac5f3f98ec201e83c034fac1651f2480e8d4727ab432d055be45cb1081731ac9
jws5-tomcat-servlet-4.0-api-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: e92fcb07a71011b9e80af911f07651803923070b7230243fd635b3c9b7e1b4a5
jws5-tomcat-webapps-9.0.87-6.redhat_00006.1.el9jws.noarch.rpm SHA-256: 0519c945bbcb4db8cd6b92f6d83fcd34a0a3d85be45ec6d37a1e0e6349293174

JBoss Enterprise Web Server 5 for RHEL 8

SRPM
jws5-tomcat-9.0.87-6.redhat_00006.1.el8jws.src.rpm SHA-256: 20310a0a8b385956cb8af991bfe6336f93bab80d8daea213c915df92f0bf6c8f
x86_64
jws5-tomcat-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 8f75bacd5b156458cc68b9bd79406b87fd89e55eb64d14aa7a874b5e9a47d029
jws5-tomcat-admin-webapps-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 4af5db10ff06e844d859780a828f650adbc397356df9c9fcdce2e051cf33fef9
jws5-tomcat-docs-webapp-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 5c0eb4a61d38854ca0d158cc5b8da8fa7d5dbe74ab78e7b9aacea3697112278e
jws5-tomcat-el-3.0-api-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: f152ae78ec4bb10a07f6b17754def752d790bb7b9a39d00ffdf7ff9a6b97e0d9
jws5-tomcat-javadoc-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 9b4ef59173ea5f70fc59da1461afcf98d7f03f9c0a9ee0399058152c8f44ea9b
jws5-tomcat-jsp-2.3-api-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 01527d94cb74e79c11723edcf4528b658176147fccceeea937e7ea61295b82ec
jws5-tomcat-lib-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 0e8aee4665e2d29aab744b4b6f1d18387c5fdb3eb30c6a9958f868ac1903bd3e
jws5-tomcat-selinux-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 5953ad083b8a5400e698c21f8172bad1879235428a68cd3f28dd3099d04a24a0
jws5-tomcat-servlet-4.0-api-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: c81079db53a25b411fa5e3ba7d3c9fd827eb28c6d8dd88730e9dd3cd1aa21a8d
jws5-tomcat-webapps-9.0.87-6.redhat_00006.1.el8jws.noarch.rpm SHA-256: 70de98133a2f55b3b78445b669570541fde11508d197a1f79edbbcb14343e057

JBoss Enterprise Web Server 5 for RHEL 7

SRPM
jws5-tomcat-9.0.87-6.redhat_00006.1.el7jws.src.rpm SHA-256: d1e90b51da8278db9e5ef56f3ece125b4176fd65c4ebb712e839df74e5e120a9
x86_64
jws5-tomcat-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: b5feb131abd45effbb2a05873ee3cb8f82aca3e1393a8676a471a9805aa614bc
jws5-tomcat-admin-webapps-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 3871e6ab5cbc7afa2434ce6b323d99770a744d82657a8c08440037a1b15f9713
jws5-tomcat-docs-webapp-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: d76402d8fb113364baf14411e27414f57a751d6aebe6febe2d37e77403d06870
jws5-tomcat-el-3.0-api-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 8faaaad7f394e573d99bb3355e09aae4885466fb28b746556569cfc4c0460c7a
jws5-tomcat-java-jdk11-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: d5ebc7a4f6602223b713a86285a67a72b643d8ed93d11374caf58dd9f669f6ed
jws5-tomcat-java-jdk8-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 512fd52cd54fede574a198243b9911e9bc027993d2a2575ec736a76a462280df
jws5-tomcat-javadoc-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 0d1cfe0cbffd31acfd2352acd10d8aa7d384713c4a6661cc77cc193030509c89
jws5-tomcat-jsp-2.3-api-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 435abe2df30727ca906528f7afc485927dda3577d93f5b606905461af7c103fc
jws5-tomcat-lib-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 2b08b5a7e3eddaa5074621600f971c95f51b8ad70e7b509b6d9779ab9c1023e6
jws5-tomcat-selinux-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 1e83ca20c57655c172c834bacf7c3cac146730b66e831d99d9057343f75ebf28
jws5-tomcat-servlet-4.0-api-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: 8b1433cfe2fe50dab6bbd55bda3afd8b498fcd9f83e06647898bcb9bafae00f8
jws5-tomcat-webapps-9.0.87-6.redhat_00006.1.el7jws.noarch.rpm SHA-256: ff165248756c2beecf6e9c1e8109f96173ddd71face567de78c525a3769cd49c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility