RHSA-2025:17298

Advisory lineage Upstream: 3 Downstream: 0
Published: 03 Oct 2025, 10:03
Last modified:07 May 2026, 10:03

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.3 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Oct 2025, 10:03
Published
Vulnerability first disclosed
07 May 2026, 10:03
Last Modified
Vulnerability information updated

Description

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.0 security update

CVSS Metrics

  • v3.1HIGHScore: 8.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Affected Systems

  • redhateap8-apache-commons-lang

    < 0:3.18.0-1.redhat_00002.1.el8eap | < 0:3.18.0-1.redhat_00002.1.el9eap

  • redhateap8-apache-cxf

    < 0:4.0.9-4.redhat_00002.1.el8eap | < 0:4.0.9-4.redhat_00002.1.el9eap

  • redhateap8-apache-cxf-rt

    < 0:4.0.9-4.redhat_00002.1.el8eap | < 0:4.0.9-4.redhat_00002.1.el9eap

  • redhateap8-apache-cxf-services

    < 0:4.0.9-4.redhat_00002.1.el8eap | < 0:4.0.9-4.redhat_00002.1.el9eap

  • redhateap8-apache-cxf-tools

    < 0:4.0.9-4.redhat_00002.1.el8eap | < 0:4.0.9-4.redhat_00002.1.el9eap

  • redhateap8-eap-product-conf-parent

    < 0:801.0.1-2.GA_redhat_00003.1.el8eap | < 0:801.0.1-2.GA_redhat_00003.1.el9eap

  • redhateap8-eap-product-conf-wildfly-ee-feature-pack

    < 0:801.0.1-2.GA_redhat_00003.1.el8eap | < 0:801.0.1-2.GA_redhat_00003.1.el9eap

  • redhateap8-jbossws-cxf

    < 0:7.3.4-1.Final_redhat_00001.1.el8eap | < 0:7.3.4-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-buffer

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-codec

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-codec-dns

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-codec-http

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-codec-socks

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-common

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-handler

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-handler-proxy

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-resolver

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-resolver-dns

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-transport

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-transport-classes-epoll

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-transport-native-epoll

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-transport-native-epoll-debuginfo

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-netty-transport-native-unix-common

    < 0:4.1.127-1.Final_redhat_00001.1.el8eap | < 0:4.1.127-1.Final_redhat_00001.1.el9eap

  • redhateap8-opensaml

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-core

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-profile-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-saml-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-saml-impl

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-security-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-security-impl

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-soap-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xacml-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xacml-impl

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xacml-saml-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xacml-saml-impl

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xmlsec-api

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-opensaml-xmlsec-impl

    < 0:4.3.2-2.redhat_00002.1.el8eap | < 0:4.3.2-2.redhat_00002.1.el9eap

  • redhateap8-wildfly

    < 0:8.1.0-55.GA_redhat_00016.1.el8eap | < 0:8.1.0-55.GA_redhat_00016.1.el9eap

  • redhateap8-wildfly-java-jdk17

    < 0:8.1.0-55.GA_redhat_00016.1.el8eap | < 0:8.1.0-55.GA_redhat_00016.1.el9eap

  • redhateap8-wildfly-java-jdk21

    < 0:8.1.0-55.GA_redhat_00016.1.el8eap | < 0:8.1.0-55.GA_redhat_00016.1.el9eap

  • redhateap8-wildfly-modules

    < 0:8.1.0-55.GA_redhat_00016.1.el8eap | < 0:8.1.0-55.GA_redhat_00016.1.el9eap

  • redhateap8-wss4j

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-bindings

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-policy

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-ws-security-common

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-ws-security-dom

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-ws-security-policy-stax

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-wss4j-ws-security-stax

    < 0:3.0.4-1.redhat_00002.1.el8eap | < 0:3.0.4-1.redhat_00002.1.el9eap

  • redhateap8-xml-security

    < 0:3.0.5-1.redhat_00001.1.el8eap | < 0:3.0.5-1.redhat_00001.1.el9eap

References (36)