Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1638 - Security Advisory
Issued:
2025-02-18
Updated:
2025-02-18

RHSA-2025:1638 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Enterprise Application Platform 7.4.21 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Enterprise Application Platform 7.4
for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update
as having a security impact of Important. A Common Vulnerability Scoring System
(CVSS) base score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.21 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.20, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.21 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • org.hornetq/hornetq-core-client: Arbitrarily overwrite files or access sensitive information [eap-7.4.z] (CVE-2024-51127)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgements, and other related information, refer to the CVE page(s)
listed in the References section.

Solution

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 7.4 for RHEL 9 x86_64

Fixes

  • BZ - 2323697 - CVE-2024-51127 hornetq-core-client: Arbitrarily overwrite files or access sensitive information
  • JBEAP-28235 - Tracker bug for the EAP 7.4.21 release for RHEL-9
  • JBEAP-27610 - [GSS](7.4.z) Upgrade Hibernate-orm from 5.3.36.Final-redhat-00001 to 5.3.37.Final-redhat-00001
  • JBEAP-28359 - [GSS](7.4.z) Upgrade HAL from 3.3.24.Final-redhat-00001 to 3.3.25.Final-redhat-00001
  • JBEAP-28587 - (7.4.x) Upgrade Apache Santuario from 2.3.4.redhat-00002 to 2.3.5.redhat-00001
  • JBEAP-28691 - [GSS](7.4.z) Upgrade opensaml from 3.3.1.redhat-00002 to 3.4.6-redhat-00001
  • JBEAP-28729 - [GSS](7.4.z) Upgrade JBossws cxf from 5.4.13.Final-redhat-00001 to 5.4.14.Final-redhat-00001
  • JBEAP-28730 - [GSS](7.4.z) Upgrade jbossws-common from 3.3.3.Final-redhat-00001 to 3.4.0.Final-redhat-00001
  • JBEAP-29200 - (7.4.z) Upgrade Wildfly Core from 15.0.40.Final-redhat-00002 to 15.0.41.Final-redhat-00001

CVEs

  • CVE-2024-51127

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 7.4 for RHEL 9

SRPM
eap7-hal-console-3.3.25-1.Final_redhat_00001.1.el9eap.src.rpm SHA-256: 0638224ed8cadc8ca8f9f9fd5167792c461538850310b3afab36c00513806026
eap7-hibernate-5.3.37-1.Final_redhat_00001.1.el9eap.src.rpm SHA-256: 81a847cdb10d6e25e63108450b6d85d549d49c4c5b145055a79a35b87218efbc
eap7-jbossws-common-3.4.0-1.Final_redhat_00001.1.el9eap.src.rpm SHA-256: cd158947dcc234f46ddc9374a654439e1f643660459b8639d4f346a515ef6c76
eap7-jbossws-cxf-5.4.14-1.Final_redhat_00001.1.el9eap.src.rpm SHA-256: a4151864150b870a54371c121f7f88695c78b0664ab725e961e57d0b1ca74e65
eap7-opensaml-3.4.6-1.redhat_00001.1.el9eap.src.rpm SHA-256: 7cc6e0f3da452afc480b438ac184d1c1f82c03b782406429778849c2d19ddb55
eap7-wildfly-7.4.21-2.GA_redhat_00001.1.el9eap.src.rpm SHA-256: e9bc5116bc51c37f3f0a29625fd522b2f243aef52169de53ec47fcf238eb5df2
eap7-xml-security-2.3.5-1.redhat_00001.1.el9eap.src.rpm SHA-256: c90a54ccae5eb56c71f10f1ebb420da464de7ca54db93ac93bc3c290fb9bb9ed
x86_64
eap7-hal-console-3.3.25-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 4e4e7451bcf0c3b2e6ae72111f2a66cd251daacf7833b8fdd3ee3ca09edab9c2
eap7-hibernate-5.3.37-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 5e64b62e1b93879909ca7f58139bde711daa00e566d0eeb6f9d72d0655c0d4bc
eap7-hibernate-core-5.3.37-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 574bdd2294bb778cd9f26d98a7cbd7d747fb6d1978e41dd96a97974661c9c637
eap7-hibernate-envers-5.3.37-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 81f2262d6f33fc6b87e8e93d206fc1bbd5981d398868a17914f0d1bcfa7cb742
eap7-jbossws-common-3.4.0-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 4dce08878990abb5cfda14305c04c3a9ddbfaf5e7859dd74c60a67fe232e6bdc
eap7-jbossws-cxf-5.4.14-1.Final_redhat_00001.1.el9eap.noarch.rpm SHA-256: 0c8344a3fde620bb6991b05219a8857a36bb7c392ac8b283bbfad93f7c32b3f2
eap7-opensaml-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: ed7f4699d67150520d7b11a6b3c24ece0f4bc3e0c531dc1944c29bac080d1fd8
eap7-opensaml-core-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 0c972934c4fc5f9287acdadcc25d7980d724ed19c3a2b5fc208913f6b5839398
eap7-opensaml-profile-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: a2732bae76da7643060aa67ee38b651103b3428c46484f458ac7d89e5ad2df51
eap7-opensaml-saml-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 308074376058865aeca1cea2b5ef24454fbe01fcfc765e852fcc8e976bc37011
eap7-opensaml-saml-impl-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 152016fb71a737b4886e706b10997eaae07ce32a44c0662e68d56057d3b78a5b
eap7-opensaml-security-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 11dc5c07a8a0df20af6eb13dabfc9e071d847382edb9b9c805f2378193432c22
eap7-opensaml-security-impl-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 882f37e373a0f6da066a690d6efeda4549cd396d3a8bc7f71e3e412502afacc3
eap7-opensaml-soap-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 2a6ea6b1002e6f2dabd6ae771f81488d4c9ec97dd73622b21cf9778f20f5e99c
eap7-opensaml-xacml-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 72901e9bdc915b8c2bc228faf2179b25469967efa8f2517c7ebc8d51afe58745
eap7-opensaml-xacml-impl-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: a571a5e490960dc0d035f203c6dc90b15ab2c269b2bed1acde4e4e883c3f1bb0
eap7-opensaml-xacml-saml-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 41583d7d703486149be6bf182c535175801bc05ff3a427f26717cccd747707fc
eap7-opensaml-xacml-saml-impl-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: e3817c2afc869c042b027d548160989e93a5f33b52b1a0d8240ca01c7a381f7d
eap7-opensaml-xmlsec-api-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: d31e67c5b26c27a6acacd197c8a4e106dcff99a2eb1386cb565fb8fe934ecef5
eap7-opensaml-xmlsec-impl-3.4.6-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: f9cad9aab622344c3132dce1fbc3760770d16cf643d12d4b46475110301f3d08
eap7-wildfly-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 171604c74880e36d5b84914c49047a597277e7d80a6ae51b4064920702936e19
eap7-wildfly-java-jdk11-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: b62aef0d6affb636496f782171fe90287de896e5483c4473a369bb65e8e4457b
eap7-wildfly-java-jdk17-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: e508c6643bd52c3f2ecbdf68bfcf0e01bcac74e4733b4b608b766f75f63776ff
eap7-wildfly-java-jdk8-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 1d1e7e4ad7ed4526ec09cd302fd8642e1d5b6a6fe02908791909d408b4be0b75
eap7-wildfly-javadocs-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 5c2c454fa74376bff76f5ae94457ee391b765535cf7bd3c526e3e43514e835bf
eap7-wildfly-modules-7.4.21-2.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 08c98f12cfd214d81599b72f72d23cb744c4501d6b2978b7578f3abfa711175a
eap7-xml-security-2.3.5-1.redhat_00001.1.el9eap.noarch.rpm SHA-256: 5e9acf22c747fd430c60dfc612476c12026a6b25a61f6b924350d12dedc4f87c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility