Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
RHSA-2025:22775
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2025:22775
Import Source
https://security.access.redhat.com/data/osv/RHSA-2025:22775.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2025:22775
Upstream
CVE-2025-4949
Published
2025-12-05T10:08:27Z
Modified
2026-01-17T10:30:09.503694Z
Severity
4.8 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.11 security update
Details
References
https://access.redhat.com/errata/RHSA-2025:22775
https://access.redhat.com/security/updates/classification/#moderate
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.0
https://access.redhat.com/articles/7120566
https://bugzilla.redhat.com/show_bug.cgi?id=2367730
https://issues.redhat.com/browse/JBEAP-28993
https://issues.redhat.com/browse/JBEAP-30584
https://issues.redhat.com/browse/JBEAP-30977
https://issues.redhat.com/browse/JBEAP-31001
https://issues.redhat.com/browse/JBEAP-31031
https://issues.redhat.com/browse/JBEAP-31074
https://issues.redhat.com/browse/JBEAP-31253
https://issues.redhat.com/browse/JBEAP-31260
https://issues.redhat.com/browse/JBEAP-31290
https://issues.redhat.com/browse/JBEAP-31339
https://issues.redhat.com/browse/JBEAP-31377
https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22775.json
https://access.redhat.com/security/cve/CVE-2025-4949
https://www.cve.org/CVERecord?id=CVE-2025-4949
https://nvd.nist.gov/vuln/detail/CVE-2025-4949
https://gitlab.eclipse.org/security/cve-assignement/-/issues/64
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/281
https://projects.eclipse.org/projects/technology.jgit/releases/7.2.1
Affected packages
Red Hat:jboss_enterprise_application_platform:8.0::el9
eap8-angus-activation
Package
Name
eap8-angus-activation
Purl
pkg:rpm/redhat/eap8-angus-activation
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.2-2.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-apache-commons-io
Package
Name
eap8-apache-commons-io
Purl
pkg:rpm/redhat/eap8-apache-commons-io
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.16.1-2.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-atinject
Package
Name
eap8-atinject
Purl
pkg:rpm/redhat/eap8-atinject
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.1-5.redhat_00007.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle
Package
Name
eap8-bouncycastle
Purl
pkg:rpm/redhat/eap8-bouncycastle
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle-jmail
Package
Name
eap8-bouncycastle-jmail
Purl
pkg:rpm/redhat/eap8-bouncycastle-jmail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle-pg
Package
Name
eap8-bouncycastle-pg
Purl
pkg:rpm/redhat/eap8-bouncycastle-pg
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle-pkix
Package
Name
eap8-bouncycastle-pkix
Purl
pkg:rpm/redhat/eap8-bouncycastle-pkix
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle-prov
Package
Name
eap8-bouncycastle-prov
Purl
pkg:rpm/redhat/eap8-bouncycastle-prov
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-bouncycastle-util
Package
Name
eap8-bouncycastle-util
Purl
pkg:rpm/redhat/eap8-bouncycastle-util
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-eap-product-conf-parent
Package
Name
eap8-eap-product-conf-parent
Purl
pkg:rpm/redhat/eap8-eap-product-conf-parent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:800.11.0-1.GA_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-eap-product-conf-wildfly-ee-feature-pack
Package
Name
eap8-eap-product-conf-wildfly-ee-feature-pack
Purl
pkg:rpm/redhat/eap8-eap-product-conf-wildfly-ee-feature-pack
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:800.11.0-1.GA_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-eclipse-jgit
Package
Name
eap8-eclipse-jgit
Purl
pkg:rpm/redhat/eap8-eclipse-jgit
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.10.1.202505221210-1.r_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hal-console
Package
Name
eap8-hal-console
Purl
pkg:rpm/redhat/eap8-hal-console
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.6.27-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hibernate
Package
Name
eap8-hibernate
Purl
pkg:rpm/redhat/eap8-hibernate
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.2.46-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hibernate-core
Package
Name
eap8-hibernate-core
Purl
pkg:rpm/redhat/eap8-hibernate-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.2.46-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hibernate-envers
Package
Name
eap8-hibernate-envers
Purl
pkg:rpm/redhat/eap8-hibernate-envers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.2.46-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hibernate-validator
Package
Name
eap8-hibernate-validator
Purl
pkg:rpm/redhat/eap8-hibernate-validator
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.2-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-hibernate-validator-cdi
Package
Name
eap8-hibernate-validator-cdi
Purl
pkg:rpm/redhat/eap8-hibernate-validator-cdi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.2-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-httpcomponents-client
Package
Name
eap8-httpcomponents-client
Purl
pkg:rpm/redhat/eap8-httpcomponents-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.5.14-5.redhat_00016.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-httpcomponents-core
Package
Name
eap8-httpcomponents-core
Purl
pkg:rpm/redhat/eap8-httpcomponents-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.4.16-6.redhat_00011.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-installation-manager-api
Package
Name
eap8-installation-manager-api
Purl
pkg:rpm/redhat/eap8-installation-manager-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.3-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-istack-commons-runtime
Package
Name
eap8-istack-commons-runtime
Purl
pkg:rpm/redhat/eap8-istack-commons-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.2-2.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-istack-commons-tools
Package
Name
eap8-istack-commons-tools
Purl
pkg:rpm/redhat/eap8-istack-commons-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.2-2.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-activation
Package
Name
eap8-jakarta-activation
Purl
pkg:rpm/redhat/eap8-jakarta-activation
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.1.3-2.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-annotation-api
Package
Name
eap8-jakarta-annotation-api
Purl
pkg:rpm/redhat/eap8-jakarta-annotation-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.1.1-5.redhat_00005.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-enterprise-concurrent
Package
Name
eap8-jakarta-enterprise-concurrent
Purl
pkg:rpm/redhat/eap8-jakarta-enterprise-concurrent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.2-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-interceptor-api
Package
Name
eap8-jakarta-interceptor-api
Purl
pkg:rpm/redhat/eap8-jakarta-interceptor-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.1.0-5.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-mail
Package
Name
eap8-jakarta-mail
Purl
pkg:rpm/redhat/eap8-jakarta-mail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.1.3-3.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-servlet-api
Package
Name
eap8-jakarta-servlet-api
Purl
pkg:rpm/redhat/eap8-jakarta-servlet-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.0.0-6.redhat_00007.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-validation-api
Package
Name
eap8-jakarta-validation-api
Purl
pkg:rpm/redhat/eap8-jakarta-validation-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.2-3.redhat_00006.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-ws-rs-api
Package
Name
eap8-jakarta-ws-rs-api
Purl
pkg:rpm/redhat/eap8-jakarta-ws-rs-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.0-5.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jakarta-xml-bind-api
Package
Name
eap8-jakarta-xml-bind-api
Purl
pkg:rpm/redhat/eap8-jakarta-xml-bind-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.2-2.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jboss-el-api_5.0_spec
Package
Name
eap8-jboss-el-api_5.0_spec
Purl
pkg:rpm/redhat/eap8-jboss-el-api_5.0_spec
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.2-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jbossws-cxf
Package
Name
eap8-jbossws-cxf
Purl
pkg:rpm/redhat/eap8-jbossws-cxf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.3.6-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jctools
Package
Name
eap8-jctools
Purl
pkg:rpm/redhat/eap8-jctools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-3.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-jctools-core
Package
Name
eap8-jctools-core
Purl
pkg:rpm/redhat/eap8-jctools-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.5-3.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-parsson
Package
Name
eap8-parsson
Purl
pkg:rpm/redhat/eap8-parsson
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1.7-3.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-reactive-streams
Package
Name
eap8-reactive-streams
Purl
pkg:rpm/redhat/eap8-reactive-streams
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.4-4.redhat_00005.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-reactivex-rxjava2
Package
Name
eap8-reactivex-rxjava2
Purl
pkg:rpm/redhat/eap8-reactivex-rxjava2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.21-4.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-saaj-impl
Package
Name
eap8-saaj-impl
Purl
pkg:rpm/redhat/eap8-saaj-impl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.4-2.redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-stax-ex
Package
Name
eap8-stax-ex
Purl
pkg:rpm/redhat/eap8-stax-ex
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.1.0-3.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-stax2-api
Package
Name
eap8-stax2-api
Purl
pkg:rpm/redhat/eap8-stax2-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.2.2-2.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-sun-istack-commons
Package
Name
eap8-sun-istack-commons
Purl
pkg:rpm/redhat/eap8-sun-istack-commons
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.2-2.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly
Package
Name
eap8-wildfly
Purl
pkg:rpm/redhat/eap8-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.11-1.GA_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-elytron
Package
Name
eap8-wildfly-elytron
Purl
pkg:rpm/redhat/eap8-wildfly-elytron
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.12-1.Final_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-elytron-tool
Package
Name
eap8-wildfly-elytron-tool
Purl
pkg:rpm/redhat/eap8-wildfly-elytron-tool
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.2.12-1.Final_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-java-jdk11
Package
Name
eap8-wildfly-java-jdk11
Purl
pkg:rpm/redhat/eap8-wildfly-java-jdk11
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.11-1.GA_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-java-jdk17
Package
Name
eap8-wildfly-java-jdk17
Purl
pkg:rpm/redhat/eap8-wildfly-java-jdk17
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.11-1.GA_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-java-jdk21
Package
Name
eap8-wildfly-java-jdk21
Purl
pkg:rpm/redhat/eap8-wildfly-java-jdk21
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.11-1.GA_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-wildfly-modules
Package
Name
eap8-wildfly-modules
Purl
pkg:rpm/redhat/eap8-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.0.11-1.GA_redhat_00002.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
eap8-yasson
Package
Name
eap8-yasson
Purl
pkg:rpm/redhat/eap8-yasson
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.4-2.redhat_00004.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2025:22775.json"
RHSA-2025:22775 - OSV