Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.4 release and security update
Red Hat JBoss Web Server 6.2.4 includes multiple security fixes addressing vulnerabilities in Apache Tomcat components such as tomcat-coyote and tomcat-catalina. These fixes resolve issues including HTTP/2 header validation, information disclosure via AJP secret timing, authentication bypasses, improper authorization, denial of service due to uncontrolled resource allocation, and security constraint bypasses. The update replaces version 6.2.3 and is available for Red Hat Enterprise Linux 8, 9, and 10.
AI Analysis
Technical Summary
This security advisory covers Red Hat JBoss Web Server 6.2.4, which addresses multiple vulnerabilities in Apache Tomcat components integrated within the server. The fixed issues include CVE-2026-41293 (HTTP/2 request headers not validated), CVE-2026-43514 (information disclosure via AJP secret timing discrepancy), CVE-2026-43512 (authentication bypass via digest authentication), CVE-2026-43513 (improper handling of case sensitivity in LockOutRealm), CVE-2026-43515 (improper authorization allowing security bypass), CVE-2026-42498 (information disclosure during WebSocket authentication), CVE-2026-41284 (denial of service due to uncontrolled resource allocation), CVE-2026-53404 (incorrect control flow in rewrite valve), and CVE-2026-55956 (improper authorization allowing security constraint bypass). These vulnerabilities affect the Apache Tomcat servlet container and related components bundled in Red Hat JBoss Web Server 6.2 on RHEL 8, 9, and 10. The update to version 6.2.4 includes bug fixes, enhancements, and component upgrades documented in the release notes. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities fixed in this update could allow attackers to bypass authentication mechanisms, disclose sensitive information, cause denial of service conditions, and bypass security constraints in the affected Apache Tomcat components. These issues could impact the confidentiality, integrity, and availability of Java web applications hosted on Red Hat JBoss Web Server 6.2 prior to version 6.2.4.
Mitigation Recommendations
Red Hat has released Red Hat JBoss Web Server 6.2.4 as a replacement for version 6.2.3, which includes fixes for all listed vulnerabilities. Users should apply this update to remediate the security issues. Before applying the update, ensure all previously released errata relevant to the system have been applied. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated beyond applying the official update.
Red Hat Security Advisory: Red Hat JBoss Web Server 6.2.4 release and security update
Description
Red Hat JBoss Web Server 6.2.4 includes multiple security fixes addressing vulnerabilities in Apache Tomcat components such as tomcat-coyote and tomcat-catalina. These fixes resolve issues including HTTP/2 header validation, information disclosure via AJP secret timing, authentication bypasses, improper authorization, denial of service due to uncontrolled resource allocation, and security constraint bypasses. The update replaces version 6.2.3 and is available for Red Hat Enterprise Linux 8, 9, and 10.
Affected software
pkg:rpm/suse/tomcat-admin-webappspkg:rpm/suse/tomcat-docs-webappRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory covers Red Hat JBoss Web Server 6.2.4, which addresses multiple vulnerabilities in Apache Tomcat components integrated within the server. The fixed issues include CVE-2026-41293 (HTTP/2 request headers not validated), CVE-2026-43514 (information disclosure via AJP secret timing discrepancy), CVE-2026-43512 (authentication bypass via digest authentication), CVE-2026-43513 (improper handling of case sensitivity in LockOutRealm), CVE-2026-43515 (improper authorization allowing security bypass), CVE-2026-42498 (information disclosure during WebSocket authentication), CVE-2026-41284 (denial of service due to uncontrolled resource allocation), CVE-2026-53404 (incorrect control flow in rewrite valve), and CVE-2026-55956 (improper authorization allowing security constraint bypass). These vulnerabilities affect the Apache Tomcat servlet container and related components bundled in Red Hat JBoss Web Server 6.2 on RHEL 8, 9, and 10. The update to version 6.2.4 includes bug fixes, enhancements, and component upgrades documented in the release notes. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities fixed in this update could allow attackers to bypass authentication mechanisms, disclose sensitive information, cause denial of service conditions, and bypass security constraints in the affected Apache Tomcat components. These issues could impact the confidentiality, integrity, and availability of Java web applications hosted on Red Hat JBoss Web Server 6.2 prior to version 6.2.4.
Mitigation Recommendations
Red Hat has released Red Hat JBoss Web Server 6.2.4 as a replacement for version 6.2.3, which includes fixes for all listed vulnerabilities. Users should apply this update to remediate the security issues. Before applying the update, ensure all previously released errata relevant to the system have been applied. Detailed update instructions are available from Red Hat's official documentation. No additional mitigation steps are indicated beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:2299-1
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-41293","CVE-2026-42498","CVE-2026-43512","CVE-2026-43513","CVE-2026-43514","CVE-2026-43515"]
- Cvss Version
- null
Threat ID: 6a27e9a88dd33fbd8516f3d4
Added to database: 06/09/2026, 10:23:36 UTC
Last enriched: 07/31/2026, 00:59:42 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 430
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.