Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:4437 - Security Advisory
Issued:
2025-05-05
Updated:
2025-05-05

RHSA-2025:4437 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Enterprise Application Platform 7.3.13 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.3.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.12, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.13 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.3.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.12, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.13 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson [eap-7.3.z] (CVE-2022-25647)
  • woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks [eap-7.3.z] (CVE-2022-40152)
  • xnio: org.xnio.StreamConnection.notifyReadClosed log to debug instead of stderr [eap-7.3.z] (CVE-2022-0084)
  • artemis-commons: Apache ActiveMQ Artemis DoS [eap-7.3] (CVE-2022-23913)
  • Moment.js: Path traversal in moment.locale [eap-7.3.z] (CVE-2022-24785)
  • jettison: memory exhaustion via user-supplied XML or JSON data [eap-7.3.z] (CVE-2022-40150)
  • snakeyaml: Denial of Service due to missing nested depth limitation for collections [eap-7.3.z] (CVE-2022-25857)
  • jettison: parser crash by stackoverflow [eap-7.3.z] (CVE-2022-40149)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 7.3 EUS 7.3 x86_64

Fixes

  • BZ - 2063601 - CVE-2022-23913 artemis-commons: Apache ActiveMQ Artemis DoS
  • BZ - 2064226 - CVE-2022-0084 xnio: org.xnio.StreamConnection.notifyReadClosed log to debug instead of stderr
  • BZ - 2072009 - CVE-2022-24785 Moment.js: Path traversal in moment.locale
  • BZ - 2080850 - CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
  • BZ - 2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections
  • BZ - 2134291 - CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks
  • BZ - 2135770 - CVE-2022-40150 jettison: memory exhaustion via user-supplied XML or JSON data
  • BZ - 2135771 - CVE-2022-40149 jettison: parser crash by stackoverflow
  • JBEAP-29297 - Tracker bug for the EAP 7.3.13 release for RHEL-7

CVEs

  • CVE-2022-0084
  • CVE-2022-23913
  • CVE-2022-24785
  • CVE-2022-25647
  • CVE-2022-25857
  • CVE-2022-40149
  • CVE-2022-40150
  • CVE-2022-40152

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/index
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 7.3 EUS 7.3

SRPM
eap7-activemq-artemis-2.9.0-10.redhat_00021.1.el7eap.src.rpm SHA-256: b215d9a71eae07218127c97d6fe863880f315bb2ab0097cbb5d8de3737149876
eap7-gson-2.8.9-1.redhat_00001.1.el7eap.src.rpm SHA-256: 513b6d03a1f40b6c1d2614a37c14f463a86ce4a2213453b39d0b756633131f95
eap7-hal-console-3.2.18-1.Final_redhat_00001.1.el7eap.src.rpm SHA-256: 2c375706bbd65fa3a73b816e244fb580cfc85492aa07c39a0e58a86c56fdd72c
eap7-jboss-server-migration-1.7.2-14.Final_redhat_00015.1.el7eap.src.rpm SHA-256: 7b0833872156ea5d60b0340e47debf91461d9223f9fc2c3120dc9e627763d6d5
eap7-jboss-xnio-base-3.7.14-3.Final_redhat_00001.1.el7eap.src.rpm SHA-256: 0cd74eab144f275d8fdc04f7609102f1126957852a78f267a949950a2830a0af
eap7-wildfly-7.3.13-4.GA_redhat_00002.1.el7eap.src.rpm SHA-256: 42a90da11daa2100fde1950cb4308198a6b96145115bb73bcc3c5195b15ff1e0
eap7-woodstox-core-6.4.0-1.redhat_00001.1.el7eap.src.rpm SHA-256: d4137d9f96c6950c12a736795a44027585b9c04262461e38436df9898dceab06
x86_64
eap7-activemq-artemis-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 52811d6ddce3b40d22497a820527ee22b9006781a8936d2bbca4ce0b99880c9a
eap7-activemq-artemis-cli-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 81f2c69bb5e3a2eb1ac2607016fc5601ddef853b0531b4712453c94981733fde
eap7-activemq-artemis-commons-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 59e339138d46267c3c1fabc729470fb027880dd2e45fb48418fee179dc3e6966
eap7-activemq-artemis-core-client-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 4a6d54035332897fa5357a74ca125278208f0ec9303cdc1e1ae1406ed3a08745
eap7-activemq-artemis-dto-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 42094e34ae2b80821a868b1d18653c046e9e65e2dcf20ef27044bb220e1da067
eap7-activemq-artemis-hornetq-protocol-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 44efc6a66b3625d70510e7ded77bb51cfd3832f6dcbd358b495e4e55ec6750e7
eap7-activemq-artemis-hqclient-protocol-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 50a79b9d3861c43afae53c632d2faab2014cfda0fee889ddbab93f1a77a47fcf
eap7-activemq-artemis-jdbc-store-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 2e3222c60f2a5e4a7966140514ac097e340a07bde03a396cb9c9d69fd32b912a
eap7-activemq-artemis-jms-client-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: f0f0439a8486c01238c11ed63b4c510f68666b8b968d3ab7b604822db1616c92
eap7-activemq-artemis-jms-server-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: edfc297e2d7611018a1b1f911762b413dc426d9cbf3b9d259a1b86543cae3797
eap7-activemq-artemis-journal-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 2610db9e5642745d35612d8fed636a12c3648a24b9eabba3326f12c3289cd7f0
eap7-activemq-artemis-ra-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 9df972836e86d89459b1f7de4fad659ba01e120aa83249054be5824ac2c05dff
eap7-activemq-artemis-selector-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 8255e86364dc7d6234f627876192c1639ef7fcd97ca980512d8d7424c975e1be
eap7-activemq-artemis-server-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: b8ae185426e8d01b16c7965d3a163b484547c56d9e288694722300dc5f00853a
eap7-activemq-artemis-service-extensions-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 42ff23f4d067dfe335a6afd15bd221e5f5fbefbd8aac97234135b491c86384ef
eap7-activemq-artemis-tools-2.9.0-10.redhat_00021.1.el7eap.noarch.rpm SHA-256: 3e67fdd136afd2fb514aa0696d837aca9fda3c9e9cd3c509b77e54818ac36029
eap7-gson-2.8.9-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 74cbe88cfcc9a5b1a008f58e1b1091d77c458d94e7424c899b8e7d51a7c4c871
eap7-hal-console-3.2.18-1.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 4d00b1b6f3d0f15e03363f9a60084d401ddeec6769c796f0ff8f52b5c2ccf041
eap7-jboss-server-migration-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: d587c9ef559fe3c9d48dc2d14c18db78d1babc9021191188b92ac48142f5cd87
eap7-jboss-server-migration-cli-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: dd62c69242a5c18dcf28b55bec8e66f31bd86b4e3ecc3c7cda6ea93cea1e0214
eap7-jboss-server-migration-core-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 9fbb2315407920813ac4df62c0bc01224d9310cd84c09f8e927c7e9eb404b7f0
eap7-jboss-server-migration-eap6.4-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 3cb5ccc787e4029ea3a340f3a8f8bbf4135b1e396ed40fab0267b47f266dd03d
eap7-jboss-server-migration-eap6.4-to-eap7.3-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: d234c07ec8d6d9a96db4fa711ce2e73d663dab8e8962a40705de15c934b9097f
eap7-jboss-server-migration-eap7.0-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 12d739529a4334952f928eac3003ea3cb0a25ef8cef28d0454096192fe2e4ea4
eap7-jboss-server-migration-eap7.1-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 67cb795ac6636f6334cc4ab6cb740e54729e9aa0a4c6a7577127e1eff23af274
eap7-jboss-server-migration-eap7.2-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 7b747caddff5062eb2a5dbd4a045ee18a3d5f427e528a1236169346430319f5a
eap7-jboss-server-migration-eap7.2-to-eap7.3-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 5e46bbb958f56fa94f0d26754f7e615ce36c323c0bea7160428951da9da6ed3d
eap7-jboss-server-migration-eap7.3-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: c0af5292c86c60bc2c9ba3c36fe4321b42ca02f4360e2a8fab2c682fbc8fba24
eap7-jboss-server-migration-wildfly10.0-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 9373aa88bd38a28c601c3460c033d7cb4770d893d2b3f432d4d3476b906db9dc
eap7-jboss-server-migration-wildfly10.1-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 8bbaed6e923a4a20b914a2497f552d1b1c2b9247ff6ac28df5d2f3fa92d28d80
eap7-jboss-server-migration-wildfly11.0-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: a73307b1b439822fad46a1545ffae706faf59d9a564c839d488469c40d559ff7
eap7-jboss-server-migration-wildfly12.0-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: fbbcb2dff18635afa621fb0d32bbf714a32f007da92295899bf82e7f3dd741ab
eap7-jboss-server-migration-wildfly13.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: d27d5d328a7b34dfd9b477fd75b32c585acf2435f8976bd415b1aa14a1fd87c7
eap7-jboss-server-migration-wildfly14.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 439c8a1d4327b016b33bbee0f2623ef177f66e94ff0b51501a66b29c5c4dce7e
eap7-jboss-server-migration-wildfly15.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 9df8dbc917557dcd2b055ac2f9866a40982d3624b6f80af98b27bc21da3f4359
eap7-jboss-server-migration-wildfly16.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 459804e56437eb5a643338dd3befb5cd7eed265c4a0419e1d146106d70acf0c6
eap7-jboss-server-migration-wildfly17.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: fc77e3f334dfdf1f8538315a42d38bd81d174a6f666687a9ac7722d4bf1fc6b0
eap7-jboss-server-migration-wildfly18.0-server-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 3dc28e8511b99d765c14e51a915465091738ef155c49d52a961b04c362244220
eap7-jboss-server-migration-wildfly8.2-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 4375888264d7ee283d7a182bc9b0802a94eb2162475619fdf6a4daa32eb9df46
eap7-jboss-server-migration-wildfly9.0-1.7.2-14.Final_redhat_00015.1.el7eap.noarch.rpm SHA-256: 45d299eb94306e0b6da579dca0bc113862688c4655b1e48f5716897b564202e2
eap7-jboss-xnio-base-3.7.14-3.Final_redhat_00001.1.el7eap.noarch.rpm SHA-256: 32b560dcd12a0e3f1e0cb1abe73d4a8defe710d86318d21840af46628db84130
eap7-wildfly-7.3.13-4.GA_redhat_00002.1.el7eap.noarch.rpm SHA-256: 4be5fd9fdf44dfebe3f2a2eb006c5b2cec0c79bf0bba7fbbaf056113b93955f1
eap7-wildfly-java-jdk11-7.3.13-4.GA_redhat_00002.1.el7eap.noarch.rpm SHA-256: b3aa5f97213384dc23f2be8921531f59bc42ba5061ca479f9b6399f128eff690
eap7-wildfly-java-jdk8-7.3.13-4.GA_redhat_00002.1.el7eap.noarch.rpm SHA-256: a6ba9a7855d649a3bb499b8d7f9678d543cec2d68fb6c784fd5176d44f1e84d1
eap7-wildfly-javadocs-7.3.13-4.GA_redhat_00002.1.el7eap.noarch.rpm SHA-256: 2d949947f08a9aa2ad84ff592460ddfc1a881bc5461e63377f64071f2064941b
eap7-wildfly-modules-7.3.13-4.GA_redhat_00002.1.el7eap.noarch.rpm SHA-256: 3257d1d5f5c70ff5d33424a0cf57da27c43ad37b026631eb3550645eeb6e7003
eap7-woodstox-core-6.4.0-1.redhat_00001.1.el7eap.noarch.rpm SHA-256: 68a3f9311212ac307f2728026ae9528c5eba9b9fc19f283ca235a73f79d69421

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility