RHSA-2023:4909MediumCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.4 release and security update

Published
September 4, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2022-24963 — apr: integer overflow/wraparound in apr_encode CVE-2023-24998 — FileUpload: FileUpload DoS with excessive parts CVE-2023-28708 — tomcat: not including the secure attribute causes information disclosure CVE-2023-28709 — tomcat: Fix for CVE-2023-24998 was incomplete

🎯 Affected products47

  • Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • Red Hat JBoss Web Server 5.7 for RHEL 8
  • Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el7jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el8jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-0:9.0.62-15.redhat_00013.1.el9jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-admin-webapps-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-admin-webapps-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-admin-webapps-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-docs-webapp-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-docs-webapp-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-docs-webapp-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-el-3.0-api-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-el-3.0-api-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-el-3.0-api-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-java-jdk11-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-java-jdk8-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-javadoc-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-javadoc-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-javadoc-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-jsp-2.3-api-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-lib-0:9.0.62-15.redhat_00013.1.el7jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • jws5-tomcat-lib-0:9.0.62-15.redhat_00013.1.el8jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 8
  • jws5-tomcat-lib-0:9.0.62-15.redhat_00013.1.el9jws.noarch as a component of Red Hat JBoss Web Server 5.7 for RHEL 9
  • jws5-tomcat-native-0:1.2.31-15.redhat_15.el7jws.src as a component of Red Hat JBoss Web Server 5.7 for RHEL 7 Server
  • +17 more not shown

✅ Remediation

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: For possible impact and workaround, please refer to: https://access.redhat.com/solutions/7004796 Workaround: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

🔗 References (7)