RHSA-2020:0861HighCVSS 7.6

Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 8 security update

Published
March 17, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2019-0221 — tomcat: XSS in SSI printenv CVE-2019-12418 — tomcat: local privilege escalation CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability

🎯 Affected products62

  • Red Hat JBoss Web Server 3.1 for RHEL 6
  • Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat-native-0:1.2.23-21.redhat_21.ep7.el6.i686 as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat-native-0:1.2.23-21.redhat_21.ep7.el6.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat-native-0:1.2.23-21.redhat_21.ep7.el6.x86_64 as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat-native-0:1.2.23-21.redhat_21.ep7.el7.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat-native-0:1.2.23-21.redhat_21.ep7.el7.x86_64 as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat-native-debuginfo-0:1.2.23-21.redhat_21.ep7.el6.i686 as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat-native-debuginfo-0:1.2.23-21.redhat_21.ep7.el6.x86_64 as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat-native-debuginfo-0:1.2.23-21.redhat_21.ep7.el7.x86_64 as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-0:7.0.70-38.ep7.el6.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-0:7.0.70-38.ep7.el7.src as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-admin-webapps-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-admin-webapps-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-docs-webapp-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-docs-webapp-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-el-2.2-api-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-el-2.2-api-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-javadoc-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-javadoc-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-jsp-2.2-api-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-jsp-2.2-api-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-jsvc-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-jsvc-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-lib-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-lib-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • tomcat7-log4j-0:7.0.70-38.ep7.el6.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 6
  • tomcat7-log4j-0:7.0.70-38.ep7.el7.noarch as a component of Red Hat JBoss Web Server 3.1 for RHEL 7
  • +32 more not shown

✅ Remediation

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: SSI is disabled in the default Tomcat configuration. The vulnerable printenv command is intended for debugging, and is recommended to not be enabled for a production website. Workaround: Disable JMX Remote if monitoring is only needed locally and there is no need to monitor Tomcat remotely. If JMX Remote is required and cannot be disabled, then use the built-in remote JMX facilities provided by the JVM. Please note that JMX Remote Lifecycle Listener is now deprecated and may be removed from both Tomcat 7 [1] and Tomcat 9 [2] after 2020-12-31. [1] https://tomcat.apache.org/tomcat-7.0-doc/config/listeners.html#Deprecated_Implementations [2] https://tomcat.apache.org/tomcat-9.0-doc/config/listeners.html#Deprecated_Implementations Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251

🔗 References (8)