Vulnerability Database
Blog
FAQ
Docs
RHSA-2025:9582
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2025:9582
Import Source
https://security.access.redhat.com/data/osv/RHSA-2025:9582.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2025:9582
Published
2025-06-25T10:06:35Z
Modified
2025-06-26T10:04:33Z
Upstream
CVE-2024-1249
CVE-2021-37136
CVE-2020-10740
CVE-2022-3143
CVE-2022-1259
CVE-2020-25644
CVE-2020-25638
CVE-2020-36518
CVE-2023-5379
CVE-2021-28170
CVE-2020-13949
CVE-2024-1233
CVE-2020-27782
CVE-2021-37137
CVE-2022-4492
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.11 on RHEL 7 security update
Details
References
https://access.redhat.com/errata/RHSA-2025:9582
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
https://bugzilla.redhat.com/show_bug.cgi?id=1834512
https://bugzilla.redhat.com/show_bug.cgi?id=1881353
https://bugzilla.redhat.com/show_bug.cgi?id=1885485
https://bugzilla.redhat.com/show_bug.cgi?id=1901304
https://bugzilla.redhat.com/show_bug.cgi?id=1928172
https://bugzilla.redhat.com/show_bug.cgi?id=1965497
https://bugzilla.redhat.com/show_bug.cgi?id=2004133
https://bugzilla.redhat.com/show_bug.cgi?id=2004135
https://bugzilla.redhat.com/show_bug.cgi?id=2064698
https://bugzilla.redhat.com/show_bug.cgi?id=2072339
https://bugzilla.redhat.com/show_bug.cgi?id=2124682
https://bugzilla.redhat.com/show_bug.cgi?id=2153260
https://bugzilla.redhat.com/show_bug.cgi?id=2242099
https://bugzilla.redhat.com/show_bug.cgi?id=2262849
https://bugzilla.redhat.com/show_bug.cgi?id=2262918
https://issues.redhat.com/browse/JBEAP-29413
https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9582.json
https://access.redhat.com/security/cve/CVE-2020-10740
https://www.cve.org/CVERecord?id=CVE-2020-10740
https://nvd.nist.gov/vuln/detail/CVE-2020-10740
https://access.redhat.com/security/cve/CVE-2020-13949
https://www.cve.org/CVERecord?id=CVE-2020-13949
https://nvd.nist.gov/vuln/detail/CVE-2020-13949
https://access.redhat.com/security/cve/CVE-2020-25638
https://www.cve.org/CVERecord?id=CVE-2020-25638
https://nvd.nist.gov/vuln/detail/CVE-2020-25638
https://access.redhat.com/security/cve/CVE-2020-25644
https://www.cve.org/CVERecord?id=CVE-2020-25644
https://nvd.nist.gov/vuln/detail/CVE-2020-25644
https://access.redhat.com/security/cve/CVE-2020-27782
https://www.cve.org/CVERecord?id=CVE-2020-27782
https://nvd.nist.gov/vuln/detail/CVE-2020-27782
https://access.redhat.com/security/cve/CVE-2020-36518
https://www.cve.org/CVERecord?id=CVE-2020-36518
https://nvd.nist.gov/vuln/detail/CVE-2020-36518
https://github.com/advisories/GHSA-57j2-w4cx-62h2
https://access.redhat.com/security/cve/CVE-2021-28170
https://www.cve.org/CVERecord?id=CVE-2021-28170
https://nvd.nist.gov/vuln/detail/CVE-2021-28170
https://securitylab.github.com/advisories/GHSL-2020-021-jakarta-el/
https://access.redhat.com/security/cve/CVE-2021-37136
https://www.cve.org/CVERecord?id=CVE-2021-37136
https://nvd.nist.gov/vuln/detail/CVE-2021-37136
https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv
https://access.redhat.com/security/cve/CVE-2021-37137
https://www.cve.org/CVERecord?id=CVE-2021-37137
https://nvd.nist.gov/vuln/detail/CVE-2021-37137
https://access.redhat.com/security/cve/CVE-2022-1259
https://www.cve.org/CVERecord?id=CVE-2022-1259
https://nvd.nist.gov/vuln/detail/CVE-2022-1259
https://access.redhat.com/security/cve/CVE-2022-3143
https://www.cve.org/CVERecord?id=CVE-2022-3143
https://nvd.nist.gov/vuln/detail/CVE-2022-3143
https://access.redhat.com/security/cve/CVE-2022-4492
https://www.cve.org/CVERecord?id=CVE-2022-4492
https://nvd.nist.gov/vuln/detail/CVE-2022-4492
https://access.redhat.com/security/cve/CVE-2023-5379
https://www.cve.org/CVERecord?id=CVE-2023-5379
https://nvd.nist.gov/vuln/detail/CVE-2023-5379
https://access.redhat.com/security/cve/CVE-2024-1233
https://www.cve.org/CVERecord?id=CVE-2024-1233
https://nvd.nist.gov/vuln/detail/CVE-2024-1233
https://github.com/advisories/GHSA-v4mm-q8fv-r2w5
https://github.com/wildfly/wildfly/pull/17812/commits/0c02350bc0d84287bed46e7c32f90b36e50d3523
https://issues.redhat.com/browse/WFLY-19226
https://access.redhat.com/security/cve/CVE-2024-1249
https://www.cve.org/CVERecord?id=CVE-2024-1249
https://nvd.nist.gov/vuln/detail/CVE-2024-1249
Affected packages
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-glassfish-el
Package
Name
eap7-glassfish-el
Purl
pkg:rpm/redhat/eap7-glassfish-el
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.1-4.b08_redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-glassfish-el-impl
Package
Name
eap7-glassfish-el-impl
Purl
pkg:rpm/redhat/eap7-glassfish-el-impl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.1-4.b08_redhat_00005.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate
Package
Name
eap7-hibernate
Purl
pkg:rpm/redhat/eap7-hibernate
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate-core
Package
Name
eap7-hibernate-core
Purl
pkg:rpm/redhat/eap7-hibernate-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate-entitymanager
Package
Name
eap7-hibernate-entitymanager
Purl
pkg:rpm/redhat/eap7-hibernate-entitymanager
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate-envers
Package
Name
eap7-hibernate-envers
Purl
pkg:rpm/redhat/eap7-hibernate-envers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate-infinispan
Package
Name
eap7-hibernate-infinispan
Purl
pkg:rpm/redhat/eap7-hibernate-infinispan
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-hibernate-java8
Package
Name
eap7-hibernate-java8
Purl
pkg:rpm/redhat/eap7-hibernate-java8
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jackson-databind
Package
Name
eap7-jackson-databind
Purl
pkg:rpm/redhat/eap7-jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jboss-ejb-client
Package
Name
eap7-jboss-ejb-client
Purl
pkg:rpm/redhat/eap7-jboss-ejb-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.12-1.Final_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-netty
Package
Name
eap7-netty
Purl
pkg:rpm/redhat/eap7-netty
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.63-2.Final_redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-netty-all
Package
Name
eap7-netty-all
Purl
pkg:rpm/redhat/eap7-netty-all
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.63-2.Final_redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-undertow
Package
Name
eap7-undertow
Purl
pkg:rpm/redhat/eap7-undertow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.18-16.SP14_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly
Package
Name
eap7-wildfly
Purl
pkg:rpm/redhat/eap7-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.11-4.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-elytron
Package
Name
eap7-wildfly-elytron
Purl
pkg:rpm/redhat/eap7-wildfly-elytron
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1.14-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-http-client
Package
Name
eap7-wildfly-http-client
Purl
pkg:rpm/redhat/eap7-wildfly-http-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-http-client-common
Package
Name
eap7-wildfly-http-client-common
Purl
pkg:rpm/redhat/eap7-wildfly-http-client-common
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-http-ejb-client
Package
Name
eap7-wildfly-http-ejb-client
Purl
pkg:rpm/redhat/eap7-wildfly-http-ejb-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-http-naming-client
Package
Name
eap7-wildfly-http-naming-client
Purl
pkg:rpm/redhat/eap7-wildfly-http-naming-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-http-transaction-client
Package
Name
eap7-wildfly-http-transaction-client
Purl
pkg:rpm/redhat/eap7-wildfly-http-transaction-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-modules
Package
Name
eap7-wildfly-modules
Purl
pkg:rpm/redhat/eap7-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.11-4.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-naming-client
Package
Name
eap7-wildfly-naming-client
Purl
pkg:rpm/redhat/eap7-wildfly-naming-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.13-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-openssl
Package
Name
eap7-wildfly-openssl
Purl
pkg:rpm/redhat/eap7-wildfly-openssl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.12-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-openssl-java
Package
Name
eap7-wildfly-openssl-java
Purl
pkg:rpm/redhat/eap7-wildfly-openssl-java
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.12-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-openssl-linux
Package
Name
eap7-wildfly-openssl-linux
Purl
pkg:rpm/redhat/eap7-wildfly-openssl-linux
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.12-6.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-openssl-linux-debuginfo
Package
Name
eap7-wildfly-openssl-linux-debuginfo
Purl
pkg:rpm/redhat/eap7-wildfly-openssl-linux-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.12-6.Final_redhat_00001.1.ep7.el7
RHSA-2025:9582 - OSV