In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.62, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2025:13680 https://access.redhat.com/errata/RHSA-2025:13680
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP1 Via RHSA-2025:13681 https://access.redhat.com/errata/RHSA-2025:13681
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:14902 https://access.redhat.com/errata/RHSA-2025:14902
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:14901 https://access.redhat.com/errata/RHSA-2025:14901
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:14903 https://access.redhat.com/errata/RHSA-2025:14903
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:15023 https://access.redhat.com/errata/RHSA-2025:15023
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:15095 https://access.redhat.com/errata/RHSA-2025:15095
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:15123 https://access.redhat.com/errata/RHSA-2025:15123
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:15516 https://access.redhat.com/errata/RHSA-2025:15516
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Via RHSA-2025:15619 https://access.redhat.com/errata/RHSA-2025:15619
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2025:15684 https://access.redhat.com/errata/RHSA-2025:15684
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:15698 https://access.redhat.com/errata/RHSA-2025:15698