RHSA-2025:9582
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.11 on RHEL 7 security update
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Systems
- redhat•eap7-glassfish-el
< 0:3.0.1-4.b08_redhat_00005.1.ep7.el7
- redhat•eap7-glassfish-el-impl
< 0:3.0.1-4.b08_redhat_00005.1.ep7.el7
- redhat•eap7-hibernate
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-hibernate-core
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-hibernate-entitymanager
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-hibernate-envers
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-hibernate-infinispan
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-hibernate-java8
< 0:5.1.17-3.Final_redhat_00004.1.ep7.el7
- redhat•eap7-jackson-databind
< 0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7
- redhat•eap7-jboss-ejb-client
< 0:4.0.12-1.Final_redhat_00002.1.ep7.el7
- redhat•eap7-netty
< 0:4.1.63-2.Final_redhat_00003.1.ep7.el7
- redhat•eap7-netty-all
< 0:4.1.63-2.Final_redhat_00003.1.ep7.el7
- redhat•eap7-undertow
< 0:1.4.18-16.SP14_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly
< 0:7.1.11-4.GA_redhat_00002.1.ep7.el7
- redhat•eap7-wildfly-elytron
< 0:1.1.14-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-http-client
< 0:1.0.21-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-http-client-common
< 0:1.0.21-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-http-ejb-client
< 0:1.0.21-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-http-naming-client
< 0:1.0.21-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-http-transaction-client
< 0:1.0.21-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-modules
< 0:7.1.11-4.GA_redhat_00002.1.ep7.el7
- redhat•eap7-wildfly-naming-client
< 0:1.0.13-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-openssl
< 0:1.0.12-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-openssl-java
< 0:1.0.12-1.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-openssl-linux
< 0:1.0.12-6.Final_redhat_00001.1.ep7.el7
- redhat•eap7-wildfly-openssl-linux-debuginfo
< 0:1.0.12-6.Final_redhat_00001.1.ep7.el7
References (69)
- https://access.redhat.com/errata/RHSA-2025:9582
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
- https://bugzilla.redhat.com/show_bug.cgi?id=1834512
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353
- https://bugzilla.redhat.com/show_bug.cgi?id=1885485
- https://bugzilla.redhat.com/show_bug.cgi?id=1901304
- https://bugzilla.redhat.com/show_bug.cgi?id=1928172
- https://bugzilla.redhat.com/show_bug.cgi?id=1965497
- https://bugzilla.redhat.com/show_bug.cgi?id=2004133
- https://bugzilla.redhat.com/show_bug.cgi?id=2004135
- https://bugzilla.redhat.com/show_bug.cgi?id=2064698
- https://bugzilla.redhat.com/show_bug.cgi?id=2072339
- https://bugzilla.redhat.com/show_bug.cgi?id=2124682
- https://bugzilla.redhat.com/show_bug.cgi?id=2153260
- https://bugzilla.redhat.com/show_bug.cgi?id=2242099
- https://bugzilla.redhat.com/show_bug.cgi?id=2262849
- https://bugzilla.redhat.com/show_bug.cgi?id=2262918
- https://issues.redhat.com/browse/JBEAP-29413
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9582.json
- https://access.redhat.com/security/cve/CVE-2020-10740
- https://www.cve.org/CVERecord?id=CVE-2020-10740
- https://nvd.nist.gov/vuln/detail/CVE-2020-10740
- https://access.redhat.com/security/cve/CVE-2020-13949
- https://www.cve.org/CVERecord?id=CVE-2020-13949
- https://nvd.nist.gov/vuln/detail/CVE-2020-13949
- https://access.redhat.com/security/cve/CVE-2020-25638
- https://www.cve.org/CVERecord?id=CVE-2020-25638
- https://nvd.nist.gov/vuln/detail/CVE-2020-25638
- https://access.redhat.com/security/cve/CVE-2020-25644
- https://www.cve.org/CVERecord?id=CVE-2020-25644
- https://nvd.nist.gov/vuln/detail/CVE-2020-25644
- https://access.redhat.com/security/cve/CVE-2020-27782
- https://www.cve.org/CVERecord?id=CVE-2020-27782
- https://nvd.nist.gov/vuln/detail/CVE-2020-27782
- https://access.redhat.com/security/cve/CVE-2020-36518
- https://www.cve.org/CVERecord?id=CVE-2020-36518
- https://nvd.nist.gov/vuln/detail/CVE-2020-36518
- https://github.com/advisories/GHSA-57j2-w4cx-62h2
- https://access.redhat.com/security/cve/CVE-2021-28170
- https://www.cve.org/CVERecord?id=CVE-2021-28170
- https://nvd.nist.gov/vuln/detail/CVE-2021-28170
- https://securitylab.github.com/advisories/GHSL-2020-021-jakarta-el/
- https://access.redhat.com/security/cve/CVE-2021-37136
- https://www.cve.org/CVERecord?id=CVE-2021-37136
- https://nvd.nist.gov/vuln/detail/CVE-2021-37136
- https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv
- https://access.redhat.com/security/cve/CVE-2021-37137
- https://www.cve.org/CVERecord?id=CVE-2021-37137
- https://nvd.nist.gov/vuln/detail/CVE-2021-37137
- https://access.redhat.com/security/cve/CVE-2022-1259
- https://www.cve.org/CVERecord?id=CVE-2022-1259
- https://nvd.nist.gov/vuln/detail/CVE-2022-1259
- https://access.redhat.com/security/cve/CVE-2022-3143
- https://www.cve.org/CVERecord?id=CVE-2022-3143
- https://nvd.nist.gov/vuln/detail/CVE-2022-3143
- https://access.redhat.com/security/cve/CVE-2022-4492
- https://www.cve.org/CVERecord?id=CVE-2022-4492
- https://nvd.nist.gov/vuln/detail/CVE-2022-4492
- https://access.redhat.com/security/cve/CVE-2023-5379
- https://www.cve.org/CVERecord?id=CVE-2023-5379
- https://nvd.nist.gov/vuln/detail/CVE-2023-5379
- https://access.redhat.com/security/cve/CVE-2024-1233
- https://www.cve.org/CVERecord?id=CVE-2024-1233
- https://nvd.nist.gov/vuln/detail/CVE-2024-1233
- https://github.com/advisories/GHSA-v4mm-q8fv-r2w5
- https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523
- https://issues.redhat.com/browse/WFLY-19226