Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2019:0451 - Security Advisory
Issued:
2019-03-04
Updated:
2019-03-04

RHSA-2019:0451 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat JBoss Web Server 5.0 Service Pack 2 security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7.

Red Hat Product Security has rated this release as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.

This release of Red Hat JBoss Web Server 5.0 Service Pack 2 serves as a replacement for Red Hat JBoss Web Server 5.0 Service Pack 1, and includes bug fixes, which are documented in the Release Notes document linked to in the References.

Security Fix(es):

  • tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)
  • tomcat: host name verification missing in WebSocket client (CVE-2018-8034)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files).

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Web Server 5 for RHEL 7 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 6 x86_64
  • JBoss Enterprise Web Server 5 for RHEL 6 i386

Fixes

  • BZ - 1579611 - CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins
  • BZ - 1607580 - CVE-2018-8034 tomcat: host name verification missing in WebSocket client

CVEs

  • CVE-2018-8014
  • CVE-2018-8034

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Web Server 5 for RHEL 7

SRPM
jws5-ecj-4.6.1-6.redhat_1.1.el7jws.src.rpm SHA-256: 6531ee655e0b2a836741a40d252634fde22ba1133dacf12c8831478d9c7e4743
jws5-javapackages-tools-3.4.1-5.15.10.el7jws.src.rpm SHA-256: 1e7ee822ac6f750c548b3114af4295d14b2e7f281fd8bd021a923d26c2af1663
jws5-jboss-logging-3.3.1-5.Final_redhat_1.1.el7jws.src.rpm SHA-256: 60e81304590fbdf20706ce622d571522677847a836a967bb29f4d60f1a987688
jws5-mod_cluster-1.4.0-9.Final_redhat_1.1.el7jws.src.rpm SHA-256: 2260c02c37786823b1302084994280463b168cd6465c0725a5b1eb146248a343
jws5-tomcat-9.0.7-17.redhat_16.1.el7jws.src.rpm SHA-256: 1e46c740a990a85380cd89c3101c6bf47780ee088cf14c73a191a2b8d4d65378
jws5-tomcat-native-1.2.17-26.redhat_26.el7jws.src.rpm SHA-256: bea881171fb62f449c0dfab444b219eaafcc1fb73dcd61b9d92a62f2309c2a47
jws5-tomcat-vault-1.1.7-5.Final_redhat_2.1.el7jws.src.rpm SHA-256: 9fe5a642813921e5ed15f32b134b1c779e5ea1f91aa0c10c88ea19558db7bef0
x86_64
jws5-ecj-4.6.1-6.redhat_1.1.el7jws.noarch.rpm SHA-256: 5cde845e69373836d59f7e29e1ef33dd2167f9f42a2c0238096e8a09e3bdcc4e
jws5-javapackages-tools-3.4.1-5.15.10.el7jws.noarch.rpm SHA-256: 12437553245af923d39bf406ff22f678c42c9659e1b3576fb2443853d4c34c2e
jws5-jboss-logging-3.3.1-5.Final_redhat_1.1.el7jws.noarch.rpm SHA-256: bbf5d089af3ff1d3c8af2f8b750cbf38a5a39b67bb2fefebf87803e896eb07e9
jws5-mod_cluster-1.4.0-9.Final_redhat_1.1.el7jws.noarch.rpm SHA-256: e1a1709f014d317463675da4af2114af7103e86d731e938e4ccbfbe39e500172
jws5-mod_cluster-tomcat-1.4.0-9.Final_redhat_1.1.el7jws.noarch.rpm SHA-256: 1c952924c76c55c49bed21bda9c75380196cec41a5631f183011d561445da26a
jws5-python-javapackages-3.4.1-5.15.10.el7jws.noarch.rpm SHA-256: eb989c502e1a41bafb59de5dc06fa3059f8d85005a9e90cb25ca757128df40ab
jws5-tomcat-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 21805ea3d55976dd2f53e085f98b2809424ac8260beafd84b8514dd8e7ad9cd3
jws5-tomcat-admin-webapps-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: a85d6ac63cf0def2f3088733bd6197c303e22064d1d94e28703ede22600575eb
jws5-tomcat-docs-webapp-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: c41cd4d6f31a4cd0429928007819ce2a014d8cf026dfa58544b7aca47ceb1452
jws5-tomcat-el-3.0-api-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 15c96dedaf7b9c131eebd95801963660d9b0961e509eba33b7e48b5aa17ac209
jws5-tomcat-javadoc-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 3b04eb7ed3e1a3509d4e6c4744867dd6641d7469237ed419d83bf38b9c3d88b8
jws5-tomcat-jsp-2.3-api-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: cc51e8127aae55e768e322e099128ea93861f41d6c7e36bf7c559413a8b7f25c
jws5-tomcat-jsvc-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 437e213e7cd236a5323c1b432419ea092cec197126881701fd021064d836ee2e
jws5-tomcat-lib-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: ed645b1f1be9961c47f4ac424ce38efab447daabfdcc7fa36d93a7a3bde0991c
jws5-tomcat-native-1.2.17-26.redhat_26.el7jws.x86_64.rpm SHA-256: 3df3ff759880c8081641b99ccae373bffb47118ce096e351955f2fc06914a0dd
jws5-tomcat-native-debuginfo-1.2.17-26.redhat_26.el7jws.x86_64.rpm SHA-256: 55c1a1575522d846ca045f255751dc8aa9eeff66839c79a4a17aa87dd676919d
jws5-tomcat-selinux-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 5d358079e7436ad24e99ed8e0605ce4889e4341d3d39db1685f84ff5b4c5260e
jws5-tomcat-servlet-4.0-api-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 48e2afa4e32724b43b2594c200a6ec9dbe09bdee7e7ca5d0978747d3cdd195a4
jws5-tomcat-vault-1.1.7-5.Final_redhat_2.1.el7jws.noarch.rpm SHA-256: 03ac118a41f716e3d56a9f80ef969160faf159562354442e093ccbd001292641
jws5-tomcat-vault-javadoc-1.1.7-5.Final_redhat_2.1.el7jws.noarch.rpm SHA-256: 6d8e940cc480cc255ce6b4f3984311a50d255b15e49a9ea00d3bfa46e396dba6
jws5-tomcat-webapps-9.0.7-17.redhat_16.1.el7jws.noarch.rpm SHA-256: 3aa02970f3232e3274724c282036ec1465a9a6d47666ba681e1c92dc45307fd0

JBoss Enterprise Web Server 5 for RHEL 6

SRPM
jws5-ecj-4.6.1-6.redhat_1.1.el6jws.src.rpm SHA-256: 070019c5b69ac401dd139672380fe6fd2c6111e22ab19038f86e507328880047
jws5-javapackages-tools-3.4.1-5.15.10.el6jws.src.rpm SHA-256: f63cbb03611e74de347e3082f70adfdaa1ddc29a9bf9c5484eabf4e9298ba314
jws5-jboss-logging-3.3.1-5.Final_redhat_1.1.el6jws.src.rpm SHA-256: cfac7e9a50c86d69695370f1d4783a2d5b3d685b9ceede256191c1c8a60a8631
jws5-mod_cluster-1.4.0-9.Final_redhat_1.1.el6jws.src.rpm SHA-256: 94607dc979e720d53a9ee5048d3ea0b73a69fffe03fd9fca9947e6b7933ec088
jws5-tomcat-9.0.7-17.redhat_16.1.el6jws.src.rpm SHA-256: 13b18c9f8865964a433a00c22a7c7716b91010267b04c6816a0c4ffa6c010a45
jws5-tomcat-native-1.2.17-26.redhat_26.el6jws.src.rpm SHA-256: c4f2c4171bcba8237386ee0879f1a2c74107eedf328167d8d5f0c0a509334657
jws5-tomcat-vault-1.1.7-5.Final_redhat_2.1.el6jws.src.rpm SHA-256: f09445c0377bb8421d3187fc4a820587674d534ac3e71dc59d4ab7f320e112b6
x86_64
jws5-ecj-4.6.1-6.redhat_1.1.el6jws.noarch.rpm SHA-256: 0327f1d2936b6f68bc790642497e2ad61c41c27654ac661b1bfef5650fc01889
jws5-javapackages-tools-3.4.1-5.15.10.el6jws.noarch.rpm SHA-256: aa58de23317675a1ebb5bc2e445ddb7fd393071195b2a68ccc724b66ece230d9
jws5-jboss-logging-3.3.1-5.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: 29ade866baf8fc1ca9718926b042da32eb0f78c38cd99b9fa7cb70d219fca9d3
jws5-mod_cluster-1.4.0-9.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: 89fb435d86c8d7216de651a4ddb3a2c29ac8ac99d2f046539c30578f6ffaba77
jws5-mod_cluster-tomcat-1.4.0-9.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: a25ce82b6315ac28a51253f39d1ddc4c627823ceef3f56e83dcb17f61d0512a4
jws5-python-javapackages-3.4.1-5.15.10.el6jws.noarch.rpm SHA-256: 71dc15f9eecb8f088e65a0bfa7a2ac5f1dcaeee595f214ca4cb6dd2163fd964b
jws5-tomcat-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 753320f26c7d0cef5b4e98d4e602a3295c7da9f78ab1dca43bee90b18f93585c
jws5-tomcat-admin-webapps-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 78ad64e6dad4d74130c331450bd44faf85e98f229f7ccdbc008ed2dffe5db0a9
jws5-tomcat-docs-webapp-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: a9052b4cb62d71bdf5ea78525356c53b3f1722620de5bdc3ba5d632248576275
jws5-tomcat-el-3.0-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 634857845527f2a4f03234797d7f716db5c14b98ae725c388a54bd5d4735700b
jws5-tomcat-javadoc-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 5d20b31594bf3ca0696a22c4fab6baa6f175413337ebc524c9dbd15ede4c3764
jws5-tomcat-jsp-2.3-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 72772be3110c48d9078e42f0a2bf84ecf413d614c53b8410a73050577be6f4b0
jws5-tomcat-jsvc-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 1815fae2991d696c1083bafe89a6337446e2120a7db59ef687431227fd28c78d
jws5-tomcat-lib-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 62799da8db6a86c73cd00c0c6eb7ed1ae274d9f1f6adb6cb68b716811f12757d
jws5-tomcat-native-1.2.17-26.redhat_26.el6jws.x86_64.rpm SHA-256: 58e86a0aed306826b4035141b9dc4cc07e87b590d5fc40d386c072fc310e26d0
jws5-tomcat-native-debuginfo-1.2.17-26.redhat_26.el6jws.x86_64.rpm SHA-256: e92c61b0b95266d348ba79f568730af7cd5057b2eb653c2c2609657a88388fd9
jws5-tomcat-selinux-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 11ddcbd2f878b38d3d0c9a260b5f799e4568f8bc4f377aa5efef12f2cc43fde9
jws5-tomcat-servlet-4.0-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: aee74aaa59c24238a15ea8ab93b83ec7cde166ce8096b603a8c770e5d9d599fd
jws5-tomcat-vault-1.1.7-5.Final_redhat_2.1.el6jws.noarch.rpm SHA-256: 4d19e90c8175b16fc1f72fff39550c0a46b65b9933d145b3d0fd929b86bbc99a
jws5-tomcat-vault-javadoc-1.1.7-5.Final_redhat_2.1.el6jws.noarch.rpm SHA-256: 5ffe1200445a18e558154f36cb59f4f8a2d425270d907bd0fdcec1cbb3ac96d9
jws5-tomcat-webapps-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 9ab06dfa24cc5b8ae7d77d0937260b5b40fee167755e0c20396c31177fdfc6ae
i386
jws5-ecj-4.6.1-6.redhat_1.1.el6jws.noarch.rpm SHA-256: 0327f1d2936b6f68bc790642497e2ad61c41c27654ac661b1bfef5650fc01889
jws5-javapackages-tools-3.4.1-5.15.10.el6jws.noarch.rpm SHA-256: aa58de23317675a1ebb5bc2e445ddb7fd393071195b2a68ccc724b66ece230d9
jws5-jboss-logging-3.3.1-5.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: 29ade866baf8fc1ca9718926b042da32eb0f78c38cd99b9fa7cb70d219fca9d3
jws5-mod_cluster-1.4.0-9.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: 89fb435d86c8d7216de651a4ddb3a2c29ac8ac99d2f046539c30578f6ffaba77
jws5-mod_cluster-tomcat-1.4.0-9.Final_redhat_1.1.el6jws.noarch.rpm SHA-256: a25ce82b6315ac28a51253f39d1ddc4c627823ceef3f56e83dcb17f61d0512a4
jws5-python-javapackages-3.4.1-5.15.10.el6jws.noarch.rpm SHA-256: 71dc15f9eecb8f088e65a0bfa7a2ac5f1dcaeee595f214ca4cb6dd2163fd964b
jws5-tomcat-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 753320f26c7d0cef5b4e98d4e602a3295c7da9f78ab1dca43bee90b18f93585c
jws5-tomcat-admin-webapps-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 78ad64e6dad4d74130c331450bd44faf85e98f229f7ccdbc008ed2dffe5db0a9
jws5-tomcat-docs-webapp-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: a9052b4cb62d71bdf5ea78525356c53b3f1722620de5bdc3ba5d632248576275
jws5-tomcat-el-3.0-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 634857845527f2a4f03234797d7f716db5c14b98ae725c388a54bd5d4735700b
jws5-tomcat-javadoc-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 5d20b31594bf3ca0696a22c4fab6baa6f175413337ebc524c9dbd15ede4c3764
jws5-tomcat-jsp-2.3-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 72772be3110c48d9078e42f0a2bf84ecf413d614c53b8410a73050577be6f4b0
jws5-tomcat-jsvc-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 1815fae2991d696c1083bafe89a6337446e2120a7db59ef687431227fd28c78d
jws5-tomcat-lib-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 62799da8db6a86c73cd00c0c6eb7ed1ae274d9f1f6adb6cb68b716811f12757d
jws5-tomcat-native-1.2.17-26.redhat_26.el6jws.i686.rpm SHA-256: f13fb969415d16ea6f3e4d93e7cb495dfd64d4dcb3d2f6c64c49a5d325f933b5
jws5-tomcat-native-debuginfo-1.2.17-26.redhat_26.el6jws.i686.rpm SHA-256: ad87dcce49d71cd7ae2bac0338d57bc7869e802923c74f194227216cceafb642
jws5-tomcat-selinux-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 11ddcbd2f878b38d3d0c9a260b5f799e4568f8bc4f377aa5efef12f2cc43fde9
jws5-tomcat-servlet-4.0-api-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: aee74aaa59c24238a15ea8ab93b83ec7cde166ce8096b603a8c770e5d9d599fd
jws5-tomcat-vault-1.1.7-5.Final_redhat_2.1.el6jws.noarch.rpm SHA-256: 4d19e90c8175b16fc1f72fff39550c0a46b65b9933d145b3d0fd929b86bbc99a
jws5-tomcat-vault-javadoc-1.1.7-5.Final_redhat_2.1.el6jws.noarch.rpm SHA-256: 5ffe1200445a18e558154f36cb59f4f8a2d425270d907bd0fdcec1cbb3ac96d9
jws5-tomcat-webapps-9.0.7-17.redhat_16.1.el6jws.noarch.rpm SHA-256: 9ab06dfa24cc5b8ae7d77d0937260b5b40fee167755e0c20396c31177fdfc6ae

The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility