-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat JBoss Web Server 5.0 Service Pack 1 security and bug fix update
Advisory ID:       RHSA-2018:2868-01
Product:           Red Hat JBoss Web Server
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:2868
Issue date:        2018-10-03
CVE Names:         CVE-2018-8037 
====================================================================
1. Summary:

An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and
Red Hat JBoss Web Server 5.0 for RHEL 7.

Red Hat Product Security has rated this release as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat JBoss Web Server 5.0 for RHEL 6 Server - noarch
Red Hat JBoss Web Server 5.0 for RHEL 7 Server - noarch

3. Description:

Red Hat JBoss Web Server is a fully integrated and certified set of
components for hosting Java web applications. It is comprised of the Apache
Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the
PicketLink Vault extension for Apache Tomcat, and the Tomcat Native
library.

This release of Red Hat JBoss Web Server 5.0 Service Pack 1 serves as a
replacement for Red Hat JBoss Web Server 5.0, and includes bug fixes, which
are documented in the Release Notes document linked to in the References.

Security Fix(es):

* tomcat: Information Disclosure (CVE-2018-8037)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

Before applying the update, back up your existing Red Hat JBoss Web Server
installation (including all applications and configuration files).

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1607582 - CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up

6. JIRA issues fixed (https://issues.redhat.com/):

JWS-1028 - Failures in jBPM embedded use case with H2 database
JWS-1064 - Update the Tomcat fork of Commons DBCP 2 to 2.4.0
JWS-1065 - Tomcat Commons Pool Update
JWS-1121 - Update the internal fork of Apache Commons DBCP 2 to abc0484 (2018-08-09) to pick up some bug fixes and enhancements
JWS-1124 - ARJUNA016082: Synchronizations are not allowed! Transaction status isActionStatus.RUNNING when running jBPM engine in KIE server deployed to Tomcat
JWS-996 - Connection leak during XATransaction in high load

7. Package List:

Red Hat JBoss Web Server 5.0 for RHEL 6 Server:

Source:
jws5-tomcat-9.0.7-12.redhat_12.1.el6jws.src.rpm

noarch:
jws5-tomcat-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-admin-webapps-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-docs-webapp-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-el-3.0-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-javadoc-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-jsp-2.3-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-jsvc-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-lib-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-selinux-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-servlet-4.0-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
jws5-tomcat-webapps-9.0.7-12.redhat_12.1.el6jws.noarch.rpm

Red Hat JBoss Web Server 5.0 for RHEL 7 Server:

Source:
jws5-tomcat-9.0.7-12.redhat_12.1.el7jws.src.rpm

noarch:
jws5-tomcat-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-admin-webapps-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-docs-webapp-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-el-3.0-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-javadoc-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-jsp-2.3-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-jsvc-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-lib-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-selinux-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-servlet-4.0-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
jws5-tomcat-webapps-9.0.7-12.redhat_12.1.el7jws.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

8. References:

https://access.redhat.com/security/cve/CVE-2018-8037
https://access.redhat.com/security/updates/classification/#important

9. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBW7TKBdzjgjWX9erEAQgv2w//b0WmHF7IhiuF2KkEgvgrPRcNbqpacOLc
MHSO0HgNUoR8mdr2Z+UFoCLZhS5kFZW03szLg2kLtLDiiQ+tpyS2vgd8yMnlflk7
IShY06vUuUWUj6IbLm3jJ5X+/rWg0TiOGzyUeMzL3sTHCztYxq0Z0DRH/O9UI5uR
Ys21MeYEk1GbufB54jac1pq9RHUOaPH96012lY9Bb2rUiqviRyPAJHo0VfNnwMT0
xhK2kJQaWr8W5wbpgnoIzROgOj9tblVrOMgKuAHV5baIum4PKj53Q7ENysj4+nda
66ArbSNqA/kBXaCzNp35WVczJwM+G11OGErJPNq2Be8zD1pUP4yFtAYS0xzYYHgh
fcm/uO9SMNGio+KAoZsK6U7e574nJ+HpmqbdrwAR8hclo2wJRDTLTPdXMvtlx5TC
4dlz4k89Q3ILMmOs/jZOXtHLAyRGJ4S+EZqGWzgx9RjWSdC6zGfe5PLWUe98mVHl
zGULna1ltafSBEzgcnNQzd7O7O3OMQaN+EQA0uTDXrfvi4KHgJHSrKOXRtG04P2w
HPblNKBCXkfKxJvATLlkfWjXqqBMKZO/wxeNSQ4iMvBHThyTDyOX9lejL+LcJQ+a
nqT4qZJOJjF/QNODxoeDJ4aJL6T+a/usR9Q6VpoYLc6+udCXx7RTe8r6tZ6sWn+M
Fz7ABRm8n7I=Mx45
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2018-2868:01 Important: Red Hat JBoss Web Server 5.0 Service

An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7

Summary

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library.
This release of Red Hat JBoss Web Server 5.0 Service Pack 1 serves as a replacement for Red Hat JBoss Web Server 5.0, and includes bug fixes, which are documented in the Release Notes document linked to in the References.
Security Fix(es):
* tomcat: Information Disclosure (CVE-2018-8037)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files).
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2018-8037 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat JBoss Web Server 5.0 for RHEL 6 Server:
Source: jws5-tomcat-9.0.7-12.redhat_12.1.el6jws.src.rpm
noarch: jws5-tomcat-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-admin-webapps-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-docs-webapp-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-el-3.0-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-javadoc-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-jsp-2.3-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-jsvc-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-lib-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-selinux-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-servlet-4.0-api-9.0.7-12.redhat_12.1.el6jws.noarch.rpm jws5-tomcat-webapps-9.0.7-12.redhat_12.1.el6jws.noarch.rpm
Red Hat JBoss Web Server 5.0 for RHEL 7 Server:
Source: jws5-tomcat-9.0.7-12.redhat_12.1.el7jws.src.rpm
noarch: jws5-tomcat-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-admin-webapps-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-docs-webapp-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-el-3.0-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-javadoc-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-jsp-2.3-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-jsvc-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-lib-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-selinux-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-servlet-4.0-api-9.0.7-12.redhat_12.1.el7jws.noarch.rpm jws5-tomcat-webapps-9.0.7-12.redhat_12.1.el7jws.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2018:2868-01
Product: Red Hat JBoss Web Server
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2868
Issued Date: : 2018-10-03
CVE Names: CVE-2018-8037

Topic

An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 andRed Hat JBoss Web Server 5.0 for RHEL 7.Red Hat Product Security has rated this release as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat JBoss Web Server 5.0 for RHEL 6 Server - noarch

Red Hat JBoss Web Server 5.0 for RHEL 7 Server - noarch


Bugs Fixed

1607582 - CVE-2018-8037 tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up

6. JIRA issues fixed (https://issues.redhat.com/):

JWS-1028 - Failures in jBPM embedded use case with H2 database

JWS-1064 - Update the Tomcat fork of Commons DBCP 2 to 2.4.0

JWS-1065 - Tomcat Commons Pool Update

JWS-1121 - Update the internal fork of Apache Commons DBCP 2 to abc0484 (2018-08-09) to pick up some bug fixes and enhancements

JWS-1124 - ARJUNA016082: Synchronizations are not allowed! Transaction status isActionStatus.RUNNING when running jBPM engine in KIE server deployed to Tomcat

JWS-996 - Connection leak during XATransaction in high load


Related News