Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2251

Опубликовано: 07 апр. 2025
Источник: redhat
CVSS3: 6.2

Описание

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packwildfly-ejb3Not affected
Red Hat JBoss Enterprise Application Platform 7.4.23wildfly-ejb3FixedRHSA-2025:1093114.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-activemq-artemisFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-apache-cxfFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-artemis-nativeFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-elytron-webFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-glassfish-jsfFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hal-consoleFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hibernate-validatorFixedRHSA-2025:1092514.07.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-ironjacamarFixedRHSA-2025:1092514.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2351678org.jboss.eap:wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
nvd
9 месяцев назад

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.

CVSS3: 6.2
github
9 месяцев назад

A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.

6.2 Medium

CVSS3