Red Hat released JBoss Enterprise Application Platform (EAP) 7.4.6, replacing EAP 7.4.5, to remediate three moderate-severity vulnerabilities in bundled components. The update fixes CVE-2022-25647, Gson deserialization of untrusted data; CVE-2021-44906, prototype pollution in the minimist dependency used by JBoss HAL; and CVE-2022-24823, a Netty issue in which world-readable temporary files could expose sensitive information. The advisory applies to EAP 7.4 deployments, including those on Red Hat Enterprise Linux 8.
Organizations running JBoss EAP 7.4 should install previously released relevant errata and upgrade to EAP 7.4.6. The release follows EAP 7.4.5, which had addressed 15 security issues across components including H2, Netty, Jackson Databind, OpenJDK, Undertow, WildFly, and ActiveMQ Artemis; Red Hat also tracked subsequent maintenance upgrades for Jackson Databind and Artemis in the 7.4.z stream.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2023:4507 for JBoss EAP 7.4 on RHEL 9, updating EAP from version 7.4.11 to 7.4.12. The update remediated Undertow OutOfMemoryError flaw CVE-2023-3223, Jackson Databind denial-of-service flaw CVE-2021-46877, and Jettison uncontrolled-recursion flaw CVE-2023-1436.
Red Hat issued Important advisory RHSA-2023:4506 for JBoss EAP 7.4 on RHEL 8, updating EAP from 7.4.11 to 7.4.12. The update remediated Undertow OutOfMemoryError flaw CVE-2023-3223, Jackson Databind denial-of-service flaw CVE-2021-46877, and Jettison uncontrolled-recursion flaw CVE-2023-1436.
Red Hat published Moderate-severity advisory RHSA-2022:5928, delivering JBoss EAP 7.4.6 to replace 7.4.5. The update addressed the Gson, minimist, and Netty vulnerabilities tracked as CVE-2022-25647, CVE-2021-44906, and CVE-2022-24823.
Red Hat issued Moderate-impact advisory RHSA-2022:5893 for JBoss EAP 7.4 on Red Hat Enterprise Linux 8, updating EAP from 7.4.5 to 7.4.6. It fixed Gson deserialization (CVE-2022-25647), minimist prototype pollution (CVE-2021-44906), and Netty world-readable temporary-file exposure (CVE-2022-24823).
Red Hat issued Moderate-severity advisory RHSA-2022:5029 for the Red Hat build of Eclipse Vert.x 4.2.7 GA on OpenShift Application Runtimes for x86_64. The update addressed jackson-databind denial of service vulnerability CVE-2020-36518 and Gson unsafe deserialization vulnerability CVE-2022-25647.
Red Hat issued Moderate-impact advisory RHSA-2022:4922 for JBoss EAP 7.4, replacing version 7.4.4 with 7.4.5. The update remediated 15 issues, including H2 remote code execution and remote JNDI class loading flaws, Netty issues, XML denial-of-service flaws, an ActiveMQ Artemis denial of service, and a Moment.js path-traversal vulnerability.
Red Hat began issuing advisories for CVE-2020-36518, a jackson-databind denial-of-service flaw in which deeply nested objects can cause a Java StackOverflow exception. The rollout included Red Hat Data Grid 8.3.1 through RHSA-2022:2232 and subsequently affected numerous other Red Hat product lines.
Red Hat issued Low-severity advisory RHSA-2022:1299, updating JBoss EAP from 7.4.3 to 7.4.4. The release upgraded Log4j to 2.17.1.redhat-00001 and remediated seven Log4j and Log4j Core flaws, including remote-code-execution, denial-of-service, SQL-injection, and unsafe-deserialization issues.
Red Hat issued Moderate advisory RHSA-2021:4679 for JBoss EAP 7.4, updating version 7.4.1 to 7.4.2. The update remediated six flaws, including Undertow HTTP/2 denial of service, WildFly local-user access, Apache MINA SSHD memory-leak denial of service, RESTEasy endpoint disclosure, and xml-security information disclosure issues.
Red Hat issued Important advisory RHSA-2021:3660 for JBoss EAP 7.4, updating it from version 7.4.0 to 7.4.1. The release remediated nine flaws including Velocity arbitrary code execution, Undertow denial-of-service issues, Netty request smuggling, Jakarta EL expression evaluation, Apache Commons IO path traversal, and WildFly XSS.
CVE-2021-21290 was published as a medium-severity local information-disclosure vulnerability affecting Netty versions before 4.1.59.Final on Unix-like systems. Netty fixed the issue in 4.1.59.Final; affected disk-based multipart upload handling could create world-readable temporary files containing sensitive data.
Red Hat Issue Tracker item JBEAP-24790 documents an upgrade of HAL in the JBoss EAP 7.4.z stream from version 3.3.17.Final-redhat-00001 to 3.3.18.Final-redhat-00001.
Red Hat Issue Tracker item JBEAP-22864 documents an upgrade of HAL in the JBoss EAP 7.4.z stream from version 3.3.8.Final-redhat-00001 to 3.3.9.Final-redhat-00001.
Red Hat Issue Tracker item JBEAP-22462 documents an upgrade of HAL in the JBoss EAP 7.4.z stream from version 3.3.7.Final-redhat-00001 to 3.3.8.Final-redhat-00001.
Red Hat Issue Tracker item JBEAP-22160 documents an upgrade of jakarta.el in the JBoss EAP 7.4.z stream from version 3.0.3.redhat-00002 to 3.0.3.redhat-00006.
Red Hat addressed CVE-2022-25647, a Gson deserialization denial-of-service vulnerability, in JBoss EAP 7.1 EUS and 7.3 EUS for RHEL 7 through RHSA-2025:4226 and RHSA-2025:4437, respectively.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
20 references tracked. Mallory keeps watching after this page renders.
issues.redhat.com
Open sourceissues.redhat.com
Open sourceissues.redhat.com
Open sourceissues.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.