Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1636 - Security Advisory
Issued:
2025-02-18
Updated:
2025-02-18

RHSA-2025:1636 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Enterprise Application Platform 7.4.21 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Enterprise Application Platform 7.4
for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update
as having a security impact of Important. A Common Vulnerability Scoring System
(CVSS) base score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.21 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.20, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.21 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • org.hornetq/hornetq-core-client: Arbitrarily overwrite files or access sensitive information [eap-7.4.z] (CVE-2024-51127)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgements, and other related information, refer to the CVE page(s)
listed in the References section.

Solution

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 7.4 for RHEL 7 x86_64

Fixes

  • BZ - 2323697 - CVE-2024-51127 hornetq-core-client: Arbitrarily overwrite files or access sensitive information
  • JBEAP-28233 - Tracker bug for the EAP 7.4.21 release for RHEL-7
  • JBEAP-27610 - [GSS](7.4.z) Upgrade Hibernate-orm from 5.3.36.Final-redhat-00001 to 5.3.37.Final-redhat-00001
  • JBEAP-28359 - [GSS](7.4.z) Upgrade HAL from 3.3.24.Final-redhat-00001 to 3.3.25.Final-redhat-00001
  • JBEAP-28587 - (7.4.x) Upgrade Apache Santuario from 2.3.4.redhat-00002 to 2.3.5.redhat-00001
  • JBEAP-28691 - [GSS](7.4.z) Upgrade opensaml from 3.3.1.redhat-00002 to 3.4.6-redhat-00001
  • JBEAP-28729 - [GSS](7.4.z) Upgrade JBossws cxf from 5.4.13.Final-redhat-00001 to 5.4.14.Final-redhat-00001
  • JBEAP-28730 - [GSS](7.4.z) Upgrade jbossws-common from 3.3.3.Final-redhat-00001 to 3.4.0.Final-redhat-00001
  • JBEAP-29200 - (7.4.z) Upgrade Wildfly Core from 15.0.40.Final-redhat-00002 to 15.0.41.Final-redhat-00001

CVEs

  • CVE-2024-51127

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 7.4 for RHEL 7

SRPM
eap7-hal-console-3.3.25-1.Final_redhat_00001.1.el7eap.src.rpm SHA-256: b1430bd42809be70088ea200332d863bfd03b52926a3663a486d2c6d17204367
eap7-hibernate-5.3.37-1.Final_redhat_00001.1.el7eap.src.rpm SHA-256: be0cd42212326b0440216da099081b82ad6d0144fe8572c0b4b1489090baaefb
eap7-jbossws-common-3.4.0-1.Final_redhat_00001.1.el7eap.src.rpm SHA-256: 72302e0273397c5ffa3c38080025ec7594eb2570743793b0f7be3c60369f7d28
eap7-jbossws-cxf-5.4.14-1.Final_redhat_00001.1.el7eap.src.rpm SHA-256: b77c407935c09853dbc0d6d69b435d2ac77067b9b99a71d7a56973badfb0dcc9
eap7-opensaml-3.4.6-1.redhat_00001.1.el7eap.src.rpm SHA-256: 27de398961c614b407f895f4291baf7d0ccf2265095aa43a89c70cc3efa658d8
eap7-wildfly-7.4.21-2.GA_redhat_00001.1.el7eap.src.rpm SHA-256: 9de5d122b2b453e4554f4a4261934ae1cf4dafe191fc442ae0ff733e850ac93a
eap7-xml-security-2.3.5-1.redhat_00001.1.el7eap.src.rpm SHA-256: 8bbaf31ecdd3d3f64017b49de9968431986798e7eea7a401458c351ab4c5c8fa
x86_64
eap7-hal-console-3.3.25-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 0f892b477668e252664330dfa196a850f89d272f4984f717e1d0c73e2435854a
eap7-hibernate-5.3.37-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 48a5138a14d309d5c2c7bbb9afe8296257cd32d6c26d29b5bf33d266fd68944d
eap7-hibernate-core-5.3.37-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: b7e1a3660b5deb46d4643fac0bc780fc103fedeee98c7709872e38aa52b8aaa6
eap7-hibernate-entitymanager-5.3.37-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: cabe987a281b64b1157991d8ed195009061119a9e1f2ceddb2070bb858f6db37
eap7-hibernate-envers-5.3.37-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 32ee9b01ea6e60de332f067a922b11db658475772087673f747cb87e8c6d9390
eap7-hibernate-java8-5.3.37-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: c525b3a9c7253a2ab95df6b5b856dd5f800a5aa9d7e471d35b00ab7483e435b7
eap7-jbossws-common-3.4.0-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 2baf910db4e6ddcc4d53867a0e2e191bf99c5894fb68bbfd9b8b266a82dcae17
eap7-jbossws-cxf-5.4.14-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 807d1932f680a0aa8d5b4a830bc2618324e4e90b2429bc78251718a98782ced2
eap7-opensaml-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 303d83891efe178b15e9d7e6958c7df3117a199a38634b16e7fa3001e753ef68
eap7-opensaml-core-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 1dd9673c674cc8f16582c8de8b08bcb03403b4cd7d63bee7cac51f969f4bc9ef
eap7-opensaml-profile-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 090299fea36097fb3bbf13936f3048adb4014284c0123cb6573490e823536d21
eap7-opensaml-saml-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 898fc51f5d5c773c175d31d0960948c7191fe72835e70962c4ae1c468a6936f3
eap7-opensaml-saml-impl-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 05d7054dadb44664ee45efe0d51b8f216e6d13d38fed2a07d47f3704f62a31e1
eap7-opensaml-security-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 8c393310ed0bca95f4f5308c00d0ab2c3844db09cc0e33795ef5a4e30411d860
eap7-opensaml-security-impl-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 591b9cdd86a16e0a79e320f73efa1a7db9d97f457fb2558e8953ecbcd0d956d8
eap7-opensaml-soap-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 54d87b5ca2d71954416dfe1539f324304970b2197ff8cff24642c1b031581727
eap7-opensaml-xacml-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 57fef87dc31226677ee0b0a10535f8b97b79741f4e520ce5d7ae921a6c155e41
eap7-opensaml-xacml-impl-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 711ca7618bea367df86b4421845efb6be5d787de21e82154fc5a226204db99e3
eap7-opensaml-xacml-saml-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: ecf9ab417b69b3411237d2a2fd938fbb395c4941a0a415f5d440c25a90a120f1
eap7-opensaml-xacml-saml-impl-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 7edbd8409fbce2304d4abe7bc85867caddef8cc589a17e03e211816cf3edd55e
eap7-opensaml-xmlsec-api-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 2ea7c466280ab2b96775ba90c38240da03c8ec9fb38a166160e086f9d355e5ab
eap7-opensaml-xmlsec-impl-3.4.6-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 4a11dffe31a43b826390b223853f5715a3c6729da3468f6cc4df59b80705cbf9
eap7-wildfly-7.4.21-2.GA_redhat_00001.1.el7eap.noarch.rpm SHA-256: 57eb7beb0c0130e4bce5a1de98c67eb499b939237e2c5f9e3175dfa81a8cd3dd
eap7-wildfly-java-jdk11-7.4.21-2.GA_redhat_00001.1.el7eap.noarch.rpm SHA-256: 60fce45d815f874ac8b457f50ce7e00901e11d3c390bf1573067360ee8bda49a
eap7-wildfly-java-jdk8-7.4.21-2.GA_redhat_00001.1.el7eap.noarch.rpm SHA-256: ff854f12415b7266e0bd6735c5d8fdce2cc52fd35bc230022631c580abee3104
eap7-wildfly-javadocs-7.4.21-2.GA_redhat_00001.1.el7eap.noarch.rpm SHA-256: 9c643f5301c282206bf348ddc6c5cb1ddc8761db98c25b5e6178f0a2f33c2b87
eap7-wildfly-modules-7.4.21-2.GA_redhat_00001.1.el7eap.noarch.rpm SHA-256: 3ade1f127a7032887a8e53dbcc3a31b757f159f646d6019f5d6170d6618dea8b
eap7-xml-security-2.3.5-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: bb7beb815cd6d6b49f4007eb0758e9a7cc41a51cd5d2f21f9ea9799dfbd2e461

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility