RHSA-2023:1663LowCVSS 7.5
Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.2 release and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-42252 — tomcat: request smuggling CVE-2022-45143 — tomcat: JsonErrorReportValve injection
🎯 Affected products38
- Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- Red Hat JBoss Web Server 5.7 for RHEL 8
- Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el7jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el8jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-0:9.0.62-13.redhat_00011.1.el9jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-admin-webapps-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-admin-webapps-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-admin-webapps-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-docs-webapp-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-docs-webapp-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-docs-webapp-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-el-3.0-api-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-el-3.0-api-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-el-3.0-api-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-java-jdk11-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-java-jdk8-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-javadoc-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-javadoc-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-jsp-2.3-api-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-jsp-2.3-api-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-jsp-2.3-api-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-lib-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- jws5-tomcat-lib-0:9.0.62-13.redhat_00011.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
- jws5-tomcat-lib-0:9.0.62-13.redhat_00011.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
- jws5-tomcat-selinux-0:9.0.62-13.redhat_00011.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
- +8 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:1663
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2141329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2158695
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1663.json