VDB
RHSA-2025%3A17317
RHSA-2025%3A17317
PUBLISHED
CVSS 8.300000190734863 HIGH
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.9 security update
Risk Scores
CVSS 3.1
8.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-cxf-xjc-runtime | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-netty-transport-native-unix-common | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-netty-buffer | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-netty-handler | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-wss4j-policy | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-opensaml-core | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-apache-cxf-rt | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-cxf-xjc-bug986 | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-opensaml-profile-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-cxf-xjc-dv | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-apache-cxf-rt | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-wss4j-ws-security-dom | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-netty-codec-http | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-opensaml-core | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-apache-cxf-services | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-opensaml-xacml-saml-impl | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-wildfly-java-jdk21 | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-opensaml-xacml-api | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el9 | eap8-netty-common | 0, 0 |
| Red Hat:jboss_enterprise_application_platform:8.0::el8 | eap8-wildfly-java-jdk11 | 0, 0 |
…and 92 more
Timeline
- Oct 3, 2025 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 7, 2026 CVE Updated
- May 19, 2026 Distribution Patch
- May 19, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:17317 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.0 article
- https://bugzilla.redhat.com/show_bug.cgi?id=2387221 report
- https://bugzilla.redhat.com/show_bug.cgi?id=2388252 report
- https://issues.redhat.com/browse/JBEAP-30760 article
- https://issues.redhat.com/browse/JBEAP-30762 article
- https://issues.redhat.com/browse/JBEAP-30888 article
- https://www.cve.org/CVERecord?id=CVE-2025-48913 advisory
- https://lists.apache.org/thread/f1nv488ztc0js4g5ml2v88mzkzslyh83 article
- https://www.cve.org/CVERecord?id=CVE-2025-55163 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-55163 advisory
- https://github.com/netty/netty/security/advisories/GHSA-prj3-ccx8-p6x4 article
- https://kb.cert.org/vuls/id/767506 article
- https://access.redhat.com/security/cve/CVE-2025-58056 report
- https://nvd.nist.gov/vuln/detail/CVE-2025-58056 advisory
- https://github.com/JLLeitschuh/unCVEed/issues/1 article
- https://github.com/netty/netty/issues/15522 article
- https://github.com/netty/netty/pull/15611 article
- https://github.com/netty/netty/security/advisories/GHSA-fghv-69vj-qj49 article
- https://access.redhat.com/security/updates/classification/#important article
…and 17 more