Skip to main content
EPSS 4.0%top 10.0%

Red Hat Security Advisory: Red Hat JBoss Web Server 6.1.3 release and security update

0
High
Published: 11/06/2025 (11/06/2025, 16:32:43 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat JBoss Web Server 6.1.3 includes important security fixes addressing multiple vulnerabilities in Apache Tomcat components. These include a directory traversal vulnerability via rewrite rules that may allow remote code execution, a denial of service issue, and a bypass of rules in the Rewrite Valve. The update replaces version 6.1.2 and is available for Red Hat Enterprise Linux 8, 9, and 10. The advisory rates the security impact as Important. Users are advised to apply this update after ensuring all prior relevant errata are installed.

Affected software

Affected versions
>=6.1.0 <6.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/28/2026, 23:28:59 UTC

Technical Analysis

This security advisory for Red Hat JBoss Web Server 6.1.3 addresses three vulnerabilities in Apache Tomcat components: CVE-2025-55752 (directory traversal via rewrite with possible remote code execution), CVE-2025-61795 (denial of service), and CVE-2025-31651 (bypass of rules in the Rewrite Valve). The release includes bug fixes, enhancements, and component upgrades, replacing version 6.1.2. The advisory is rated as Important by Red Hat Product Security. The update is available for JBoss Web Server 6.1 on Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory, and no known exploits in the wild have been reported.

Potential Impact

The vulnerabilities fixed in this update could allow attackers to perform directory traversal potentially leading to remote code execution, cause denial of service conditions, or bypass rewrite rules in Apache Tomcat's Rewrite Valve. These issues affect the security and stability of Java web applications hosted on Red Hat JBoss Web Server 6.1. Prior versions before 6.1.3 are vulnerable to these issues. No known active exploitation has been reported at this time.

Mitigation Recommendations

A security update to Red Hat JBoss Web Server 6.1.3 is available that addresses these vulnerabilities. Users should apply this update to affected systems running Red Hat JBoss Web Server 6.1 on RHEL 8, 9, or 10. Before applying the update, ensure all previously released errata relevant to the system have been applied. Refer to Red Hat's official update instructions at https://access.redhat.com/articles/11258 for detailed guidance. No additional mitigations are specified in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:19809
Cve Count
3
Additional Cves
["CVE-2025-55752","CVE-2025-61795"]

Threat ID: 6a2929b98dd33fbd8517f8bd

Added to database: 06/10/2026, 09:09:13 UTC

Last enriched: 06/28/2026, 23:28:59 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 126

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses