Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.14 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-3884 — undertow: OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded CVE-2025-48913 — org.apache.cxf/cxf: CXF JMS Code Execution Vulnerability CVE-2026-0603 — org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection
🎯 Affected products20
- Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-apache-cxf-0:3.1.16-6.redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-apache-cxf-0:3.1.16-6.redhat_00006.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-apache-cxf-rt-0:3.1.16-6.redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-apache-cxf-services-0:3.1.16-6.redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-apache-cxf-tools-0:3.1.16-6.redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-core-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-entitymanager-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-envers-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-infinispan-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-java8-0:5.1.17-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-jbossws-cxf-0:5.1.11-1.SP1_redhat_00001.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-jbossws-cxf-0:5.1.11-1.SP1_redhat_00001.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-undertow-0:1.4.18-19.SP17_redhat_00001.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-undertow-0:1.4.18-19.SP17_redhat_00001.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-0:7.1.14-4.GA_redhat_00003.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-0:7.1.14-4.GA_redhat_00003.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-modules-0:7.1.14-4.GA_redhat_00003.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters. Workaround: To reduce risk, deployments should restrict the allowed protocols in JMS configuration to trusted and expected values only. In particular, disallow the use of rmi:// and ldap:// URLs, which could be abused for remote class loading and code execution. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:6012
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/7.1.0_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275287
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2387221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2427147
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6012.json