Red Hat Security Advisory: Red Hat JBoss Web Server 6.1.3 release and security update
Red Hat JBoss Web Server 6.1.3 includes important security fixes addressing multiple vulnerabilities in Apache Tomcat components. These include a directory traversal vulnerability via rewrite rules that may allow remote code execution, a denial of service issue, and a bypass of rules in the Rewrite Valve. The update replaces version 6.1.2 and is available for Red Hat Enterprise Linux 8, 9, and 10. The advisory rates the security impact as Important. Users are advised to apply this update after ensuring all prior relevant errata are installed.
AI Analysis
Technical Summary
This security advisory for Red Hat JBoss Web Server 6.1.3 addresses three vulnerabilities in Apache Tomcat components: CVE-2025-55752 (directory traversal via rewrite with possible remote code execution), CVE-2025-61795 (denial of service), and CVE-2025-31651 (bypass of rules in the Rewrite Valve). The release includes bug fixes, enhancements, and component upgrades, replacing version 6.1.2. The advisory is rated as Important by Red Hat Product Security. The update is available for JBoss Web Server 6.1 on Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory, and no known exploits in the wild have been reported.
Potential Impact
The vulnerabilities fixed in this update could allow attackers to perform directory traversal potentially leading to remote code execution, cause denial of service conditions, or bypass rewrite rules in Apache Tomcat's Rewrite Valve. These issues affect the security and stability of Java web applications hosted on Red Hat JBoss Web Server 6.1. Prior versions before 6.1.3 are vulnerable to these issues. No known active exploitation has been reported at this time.
Mitigation Recommendations
A security update to Red Hat JBoss Web Server 6.1.3 is available that addresses these vulnerabilities. Users should apply this update to affected systems running Red Hat JBoss Web Server 6.1 on RHEL 8, 9, or 10. Before applying the update, ensure all previously released errata relevant to the system have been applied. Refer to Red Hat's official update instructions at https://access.redhat.com/articles/11258 for detailed guidance. No additional mitigations are specified in the advisory.
Red Hat Security Advisory: Red Hat JBoss Web Server 6.1.3 release and security update
Description
Red Hat JBoss Web Server 6.1.3 includes important security fixes addressing multiple vulnerabilities in Apache Tomcat components. These include a directory traversal vulnerability via rewrite rules that may allow remote code execution, a denial of service issue, and a bypass of rules in the Rewrite Valve. The update replaces version 6.1.2 and is available for Red Hat Enterprise Linux 8, 9, and 10. The advisory rates the security impact as Important. Users are advised to apply this update after ensuring all prior relevant errata are installed.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory for Red Hat JBoss Web Server 6.1.3 addresses three vulnerabilities in Apache Tomcat components: CVE-2025-55752 (directory traversal via rewrite with possible remote code execution), CVE-2025-61795 (denial of service), and CVE-2025-31651 (bypass of rules in the Rewrite Valve). The release includes bug fixes, enhancements, and component upgrades, replacing version 6.1.2. The advisory is rated as Important by Red Hat Product Security. The update is available for JBoss Web Server 6.1 on Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory, and no known exploits in the wild have been reported.
Potential Impact
The vulnerabilities fixed in this update could allow attackers to perform directory traversal potentially leading to remote code execution, cause denial of service conditions, or bypass rewrite rules in Apache Tomcat's Rewrite Valve. These issues affect the security and stability of Java web applications hosted on Red Hat JBoss Web Server 6.1. Prior versions before 6.1.3 are vulnerable to these issues. No known active exploitation has been reported at this time.
Mitigation Recommendations
A security update to Red Hat JBoss Web Server 6.1.3 is available that addresses these vulnerabilities. Users should apply this update to affected systems running Red Hat JBoss Web Server 6.1 on RHEL 8, 9, or 10. Before applying the update, ensure all previously released errata relevant to the system have been applied. Refer to Red Hat's official update instructions at https://access.redhat.com/articles/11258 for detailed guidance. No additional mitigations are specified in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:19809
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-55752","CVE-2025-61795"]
Threat ID: 6a2929b98dd33fbd8517f8bd
Added to database: 06/10/2026, 09:09:13 UTC
Last enriched: 06/28/2026, 23:28:59 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 126
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.