VDB
RHSA-2025%3A17298
RHSA-2025%3A17298
PUBLISHED
CVSS 8.300000190734863 HIGH
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.0 security update
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-eap-product-conf-parent | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-netty-resolver-dns | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-apache-cxf-rt | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-apache-commons-lang | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-opensaml-xacml-saml-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-netty-transport-native-unix-common | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-wildfly-java-jdk17 | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-apache-cxf-services | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-opensaml-xacml-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-opensaml-xmlsec-impl | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-netty-codec-dns | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-apache-cxf-tools | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-opensaml-security-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-netty | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-opensaml-xacml-saml-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-netty-transport-classes-epoll | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-opensaml-soap-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-opensaml-profile-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el8 | eap8-eap-product-conf-wildfly-ee-feature-pack | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.1::el9 | eap8-netty-transport-native-epoll-debuginfo | 0, 0 |
…and 80 more
Timeline
- Oct 3, 2025 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 7, 2026 CVE Updated
- May 19, 2026 Distribution Patch
- May 19, 2026 Security Advisory
- May 19, 2026 Security Advisory
- May 19, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important article
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1 article
- https://bugzilla.redhat.com/show_bug.cgi?id=2388252 report
- https://issues.redhat.com/browse/JBEAP-30701 article
- https://issues.redhat.com/browse/JBEAP-30732 article
- https://issues.redhat.com/browse/JBEAP-30763 article
- https://issues.redhat.com/browse/JBEAP-30889 article
- https://issues.redhat.com/browse/JBEAP-30916 article
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_17298.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2387221 report
- https://www.cve.org/CVERecord?id=CVE-2025-48913 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-55163 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-55163 advisory
- https://github.com/netty/netty/security/advisories/GHSA-prj3-ccx8-p6x4 article
- https://kb.cert.org/vuls/id/767506 article
- https://access.redhat.com/security/cve/CVE-2025-58056 report
- https://datatracker.ietf.org/doc/html/rfc9112#name-chunked-transfer-coding article
- https://github.com/netty/netty/commit/edb55fd8e0a3bcbd85881e423464f585183d1284 article
- https://github.com/netty/netty/issues/15522 article
- https://access.redhat.com/errata/RHSA-2025:17298 advisory
…and 16 more