Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.24 security update
Red Hat JBoss Enterprise Application Platform 7.4.24 includes multiple security fixes addressing vulnerabilities such as HTTP header parsing flaws, code execution, DDoS, XXE, SQL injection, and out-of-memory conditions. These issues affect components like Undertow, CXF, Netty, Eclipse JGit, and Hibernate. The update replaces version 7.4.23 and is rated as important by Red Hat Product Security.
AI Analysis
Technical Summary
This advisory covers a security update for Red Hat JBoss Enterprise Application Platform 7.4.24, which addresses several vulnerabilities across its components. Notable fixes include CVE-2024-3884 (OutOfMemory in undertow when parsing application/x-www-form-urlencoded data), CVE-2025-12543 (Undertow HTTP server failing to reject malformed host headers leading to potential cache poisoning and SSRF), CVE-2025-48913 (CXF JMS code execution vulnerability), CVE-2025-55163 and CVE-2025-9784 (HTTP/2 DDoS vulnerabilities in Netty and Undertow), CVE-2025-4949 (XXE in Eclipse JGit), and CVE-2026-0603 (Hibernate second-order SQL injection causing information disclosure and data deletion). The update is intended to fix these issues in the 7.4.z branch of the platform. Red Hat rates the security impact as Important and provides the update as a replacement for version 7.4.23.
Potential Impact
The vulnerabilities fixed in this update can lead to denial of service via OutOfMemory or HTTP/2 DDoS attacks, remote code execution through JMS, information disclosure and data deletion via SQL injection, server-side request forgery and cache poisoning through malformed host headers, and XML external entity (XXE) attacks. These impacts affect the confidentiality, integrity, and availability of systems running affected versions of Red Hat JBoss Enterprise Application Platform 7.4.
Mitigation Recommendations
A security update to Red Hat JBoss Enterprise Application Platform 7.4.24 is available and should be applied to remediate these vulnerabilities. Before applying the update, ensure all previously released errata are applied and back up existing installations including applications and configurations. Follow Red Hat's official guidance for applying the update at https://access.redhat.com/articles/11258. No additional mitigations are specified beyond applying this update.
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.24 security update
Description
Red Hat JBoss Enterprise Application Platform 7.4.24 includes multiple security fixes addressing vulnerabilities such as HTTP header parsing flaws, code execution, DDoS, XXE, SQL injection, and out-of-memory conditions. These issues affect components like Undertow, CXF, Netty, Eclipse JGit, and Hibernate. The update replaces version 7.4.23 and is rated as important by Red Hat Product Security.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers a security update for Red Hat JBoss Enterprise Application Platform 7.4.24, which addresses several vulnerabilities across its components. Notable fixes include CVE-2024-3884 (OutOfMemory in undertow when parsing application/x-www-form-urlencoded data), CVE-2025-12543 (Undertow HTTP server failing to reject malformed host headers leading to potential cache poisoning and SSRF), CVE-2025-48913 (CXF JMS code execution vulnerability), CVE-2025-55163 and CVE-2025-9784 (HTTP/2 DDoS vulnerabilities in Netty and Undertow), CVE-2025-4949 (XXE in Eclipse JGit), and CVE-2026-0603 (Hibernate second-order SQL injection causing information disclosure and data deletion). The update is intended to fix these issues in the 7.4.z branch of the platform. Red Hat rates the security impact as Important and provides the update as a replacement for version 7.4.23.
Potential Impact
The vulnerabilities fixed in this update can lead to denial of service via OutOfMemory or HTTP/2 DDoS attacks, remote code execution through JMS, information disclosure and data deletion via SQL injection, server-side request forgery and cache poisoning through malformed host headers, and XML external entity (XXE) attacks. These impacts affect the confidentiality, integrity, and availability of systems running affected versions of Red Hat JBoss Enterprise Application Platform 7.4.
Mitigation Recommendations
A security update to Red Hat JBoss Enterprise Application Platform 7.4.24 is available and should be applied to remediate these vulnerabilities. Before applying the update, ensure all previously released errata are applied and back up existing installations including applications and configurations. Follow Red Hat's official guidance for applying the update at https://access.redhat.com/articles/11258. No additional mitigations are specified beyond applying this update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:6012
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-48913","CVE-2026-0603"]
- Cvss Version
- 3.1
Threat ID: 6a160984e29bf47b506515c9
Added to database: 05/26/2026, 20:58:44 UTC
Last enriched: 07/20/2026, 21:47:25 UTC
Last updated: 07/31/2026, 19:55:28 UTC
Views: 155
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.