Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:11741 - Security Advisory
Issued:
2025-07-30
Updated:
2025-07-30

RHSA-2025:11741 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Web Server 6.1.1 release and security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat JBoss Web Server 6.1.1 is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 6.1.1 serves as a replacement for Red Hat JBoss Web Server 6.1.0. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section.

Security Fix(es):

  • tomcat: Apache Tomcat DoS in multipart upload [jws-6] (CVE-2025-48988)
  • tomcat-catalina: Apache Tomcat: Security constraint bypass for pre/post-resources [jws-6] (CVE-2025-49125)
  • tomcat: Apache Commons FileUpload DoS via part headers [jws-6] (CVE-2025-48976)
  • jws6-tomcat: Apache Tomcat denial of service [jws-6] (CVE-2025-53506)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 6 for RHEL 10 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 9 x86_64
  • JBoss Enterprise Web Server 6 for RHEL 8 x86_64

Fixes

  • BZ - 2373015 - CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload
  • BZ - 2373018 - CVE-2025-49125 tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources
  • BZ - 2373020 - CVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers

CVEs

  • CVE-2025-48976
  • CVE-2025-48988
  • CVE-2025-49125
  • CVE-2025-53506

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.1/html/red_hat_jboss_web_server_6.1_service_pack_1_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 6 for RHEL 10

SRPM
jws6-tomcat-10.1.36-7.redhat_00008.1.el10jws.src.rpm SHA-256: fbc60691e0fbc45b7eb83dc3c6b54de92e3c6c3dea0e200fb49b1227d7f9ea25
x86_64
jws6-tomcat-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: abeafa7095ddb7908f06f23a88040650728cafb39626b44c3e4f22ffe9c3d19a
jws6-tomcat-admin-webapps-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: d9ea6d87fac571a66d70f23b81443e7c27aed87175a66155f50e23159ddf0a0c
jws6-tomcat-docs-webapp-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 226386893238b19b14e7183c4453be603774a5c5a3e37893baf6c680f991fd00
jws6-tomcat-el-5.0-api-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 3fdd77710c7dcc6e483897c271931d917792b0f42909970c1a9472f3d746e4d1
jws6-tomcat-javadoc-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: a63543528974612902ae593d726d1bf6c22bd1613a5f5ac0382025624c608863
jws6-tomcat-jsp-3.1-api-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 68b273cd11326d686da62024f6718a8ff836c8ebc671bb4e867098d5eeaa3a24
jws6-tomcat-lib-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 687d08fd8cca421a61fee5ae47caefa0b99c597d8ac4acb8c03023526d35ebce
jws6-tomcat-selinux-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: c1b3f65e128b582c7532fba77df1d7dfc252c1c590c5b79a5fc0647a631d0d60
jws6-tomcat-servlet-6.0-api-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 83845d3e4a3ee8163218d05ae45adda7f6d31bee24e9e0de0f5de55e947e99bd
jws6-tomcat-webapps-10.1.36-7.redhat_00008.1.el10jws.noarch.rpm SHA-256: 2174ccbf105fab56f93efb811ba2e2679c20f8446fe850ba3a40523debe44a2d

JBoss Enterprise Web Server 6 for RHEL 9

SRPM
jws6-tomcat-10.1.36-7.redhat_00008.1.el9jws.src.rpm SHA-256: 70a7ebdaf0befd1c37eb63b4e255f9ac3288d85356ec9130af184c2aa2a93eb9
x86_64
jws6-tomcat-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 6ed518b1dbe7bf9f7f8eef5b607c5c12ee4ecb1e716ffe6a906554dfd84480a6
jws6-tomcat-admin-webapps-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: f8e610955abf31df24ded7ad0417c19d9c63eebce7dfb637f1df2c92c0b5e145
jws6-tomcat-docs-webapp-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 04a1f4ef4c6b5bec1932ec9742da9aabcec864cfc0274a12a6abfbfb6f99f306
jws6-tomcat-el-5.0-api-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: a5e1983712d7f40cc9caee1ceef2e14797a0f8cfd14406ba7b71ca068125b1ad
jws6-tomcat-javadoc-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 4ed4d70e0fc57b90b7e241db3e36bdf250e6be2dd333f3f8b946983aa724508a
jws6-tomcat-jsp-3.1-api-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: ec4e9a5181f4372248a4636447e57dfa5c9806370bf9801b907f74c1bf095377
jws6-tomcat-lib-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 86c044bbd1916c7facd9967224679458c939cf12cf54bbc09ecad2ada69a28dc
jws6-tomcat-selinux-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 1fb4ab2765481adada36c8c78739b1e810cbf1dc73fce11e25b44ae2fd507ed0
jws6-tomcat-servlet-6.0-api-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: d99876cbaa65e1319c6eb8264d52c105024dbaf5ade528aeeb1c3f89780fc86b
jws6-tomcat-webapps-10.1.36-7.redhat_00008.1.el9jws.noarch.rpm SHA-256: 702a96d001031da8bf483fcda62c96bd69448845342cc81de19e2d3028f486c4

JBoss Enterprise Web Server 6 for RHEL 8

SRPM
jws6-tomcat-10.1.36-7.redhat_00008.1.el8jws.src.rpm SHA-256: 5bf5e91c9a7403398805bda1f638e93807cca7bab5e42f8fa17907fb6fd1f163
x86_64
jws6-tomcat-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: d44b755f880c84a83f1f42052ed4afd51b6eca38004f1d38080b289ab7d8bc34
jws6-tomcat-admin-webapps-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: 1cfb83f6bd513d227f8989674d9116c1bc9c5adebded06c8891e0b5173d016c2
jws6-tomcat-docs-webapp-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: 98999c138ce675e1b122525e4db12505d1e19492cd61a29e99c710803e4ae086
jws6-tomcat-el-5.0-api-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: f3c664681fb1a477a4827eb915e129facaa5297873a2ad610a46573d24a661ce
jws6-tomcat-javadoc-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: c420ae07519a4037c64aa6d0c6f434bdced43b37c6f310416d2d4849088b3deb
jws6-tomcat-jsp-3.1-api-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: c74cc884ddb667604fa46a6f65f5ab6c8e215a8b81544f9763b9a0d7b479957c
jws6-tomcat-lib-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: 3f84e9db3f1584074ddd0c7700ec4f4953d64bc6c1bde7896ebfa7b1ae62b3b1
jws6-tomcat-selinux-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: 57b12a5a25ece8f9b68d0d3fd57418fa6b728315e2b16fdda23e8edf9cd4a5d9
jws6-tomcat-servlet-6.0-api-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: cc166840a3d06e5b58e50446986ca180ecf3ebfafd31ce1103107a69194daf3f
jws6-tomcat-webapps-10.1.36-7.redhat_00008.1.el8jws.noarch.rpm SHA-256: 32273e4aa9edf5a6e65fbc0d13499d29205b12957794897b78275b85592529f3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility