First published: Thu Jun 30 2022(Updated: )
Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on the WildFly application runtime.<br>This release of Red Hat JBoss Enterprise Application Platform 6.4.24 serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.23 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 6.4.24 Release Notes for information about the most significant bug fixes and enhancements included in this release.<br>Security Fix(es):<br><li> tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS (CVE-2020-13935)</li> <li> jbossweb: Incomplete fix of CVE-2020-13935 for WebSocket in JBossWeb could lead to DoS (CVE-2020-14384)</li> <li> log4j: SQL injection in Log4j 1.x when application is configured to use JDBCAppender (CVE-2022-23305)</li> <li> log4j: Unsafe deserialization flaw in Chainsaw log viewer (CVE-2022-23307)</li> <li> log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender (CVE-2021-4104)</li> <li> log4j: Remote code execution in Log4j 1.x when application is configured to use JMSSink (CVE-2022-23302)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jboss-as-appclient | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cli | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-client-all | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-clustering | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cmp | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-configadmin | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-connector | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller-client | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-core-security | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-repository | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-scanner | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-http | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-management | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee-deployment | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ejb3 | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-embedded | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-host-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jacorb | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxr | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxrs | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jdr | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jmx | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jpa | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsf | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsr77 | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-logging | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-mail | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-management-client-content | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-messaging | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-modcluster | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-naming | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-network | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-configadmin | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-service | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-picketlink | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-platform-mbean | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-pojo | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-process-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-protocol | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-remoting | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-sar | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-security | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-server | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-system-jmx | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-threads | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-transactions | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-version | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-web | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-webservices | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-weld | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-xts | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-appclient | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-bundles | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-core | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-domain | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-javadocs | <7.5.24-1.Final_redhat_00001.1.ep6.el7 | 7.5.24-1.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-modules-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-product-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-standalone | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-welcome-content-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossts | <4.17.45-2.Final_redhat_2.1.ep6.el7 | 4.17.45-2.Final_redhat_2.1.ep6.el7 |
redhat/jbossweb | <7.5.32-2.Final_redhat_1.2.ep6.el7 | 7.5.32-2.Final_redhat_1.2.ep6.el7 |
redhat/jboss-as-appclient | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cli | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-client-all | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-clustering | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-cmp | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-configadmin | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-connector | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-controller-client | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-core-security | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-repository | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-deployment-scanner | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-http | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-domain-management | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ee-deployment | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-ejb3 | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-embedded | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-host-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jacorb | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxr | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jaxrs | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jdr | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jmx | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jpa | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsf | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-jsr77 | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-logging | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-mail | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-management-client-content | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-messaging | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-modcluster | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-naming | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-network | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-configadmin | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-osgi-service | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-picketlink | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-platform-mbean | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-pojo | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-process-controller | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-protocol | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-remoting | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-sar | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-security | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-server | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-system-jmx | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-threads | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-transactions | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-version | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-web | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-webservices | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-weld | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jboss-as-xts | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-appclient | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-bundles | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-core | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-domain | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-javadocs | <7.5.24-1.Final_redhat_00001.1.ep6.el7 | 7.5.24-1.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-modules-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-product-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-standalone | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossas-welcome-content-eap | <7.5.24-2.Final_redhat_00001.1.ep6.el7 | 7.5.24-2.Final_redhat_00001.1.ep6.el7 |
redhat/jbossts | <4.17.45-2.Final_redhat_2.1.ep6.el7 | 4.17.45-2.Final_redhat_2.1.ep6.el7 |
redhat/jbossweb | <7.5.32-2.Final_redhat_1.2.ep6.el7 | 7.5.32-2.Final_redhat_1.2.ep6.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.