Vulnerability Database
Blog
FAQ
Docs
RHSA-2025:1746
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2025:1746
Import Source
https://security.access.redhat.com/data/osv/RHSA-2025:1746.json
JSON Data
https://api.test.osv.dev/v1/vulns/RHSA-2025:1746
Related
CVE-2020-10672
CVE-2020-10673
CVE-2020-13936
CVE-2020-8840
CVE-2020-9546
CVE-2020-9547
CVE-2020-9548
CVE-2021-3717
CVE-2021-44228
CVE-2021-45046
CVE-2022-1471
CVE-2022-41881
CVE-2022-42003
CVE-2022-42004
CVE-2022-42889
CVE-2022-45047
CVE-2022-45693
CVE-2022-46363
Published
2025-02-24T10:02:47Z
Modified
2025-03-13T10:06:37Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.9 on RHEL 7 security update
Details
References
https://access.redhat.com/errata/RHSA-2025:1746
https://access.redhat.com/security/updates/classification/#critical
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
https://bugzilla.redhat.com/show_bug.cgi?id=1815470
https://bugzilla.redhat.com/show_bug.cgi?id=1815495
https://bugzilla.redhat.com/show_bug.cgi?id=1816330
https://bugzilla.redhat.com/show_bug.cgi?id=1816332
https://bugzilla.redhat.com/show_bug.cgi?id=1816337
https://bugzilla.redhat.com/show_bug.cgi?id=1816340
https://bugzilla.redhat.com/show_bug.cgi?id=1937440
https://bugzilla.redhat.com/show_bug.cgi?id=1991305
https://bugzilla.redhat.com/show_bug.cgi?id=2030932
https://bugzilla.redhat.com/show_bug.cgi?id=2032580
https://bugzilla.redhat.com/show_bug.cgi?id=2135244
https://bugzilla.redhat.com/show_bug.cgi?id=2135247
https://bugzilla.redhat.com/show_bug.cgi?id=2135435
https://bugzilla.redhat.com/show_bug.cgi?id=2145194
https://bugzilla.redhat.com/show_bug.cgi?id=2150009
https://bugzilla.redhat.com/show_bug.cgi?id=2153379
https://bugzilla.redhat.com/show_bug.cgi?id=2155681
https://bugzilla.redhat.com/show_bug.cgi?id=2155970
https://issues.redhat.com/browse/JBEAP-28583
https://issues.redhat.com/browse/JBEAP-28817
https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1746.json
https://access.redhat.com/security/cve/CVE-2020-8840
https://www.cve.org/CVERecord?id=CVE-2020-8840
https://nvd.nist.gov/vuln/detail/CVE-2020-8840
https://access.redhat.com/security/cve/CVE-2020-9546
https://www.cve.org/CVERecord?id=CVE-2020-9546
https://nvd.nist.gov/vuln/detail/CVE-2020-9546
https://access.redhat.com/security/cve/CVE-2020-9547
https://www.cve.org/CVERecord?id=CVE-2020-9547
https://nvd.nist.gov/vuln/detail/CVE-2020-9547
https://access.redhat.com/security/cve/CVE-2020-9548
https://www.cve.org/CVERecord?id=CVE-2020-9548
https://nvd.nist.gov/vuln/detail/CVE-2020-9548
https://access.redhat.com/security/cve/CVE-2020-10672
https://www.cve.org/CVERecord?id=CVE-2020-10672
https://nvd.nist.gov/vuln/detail/CVE-2020-10672
https://access.redhat.com/security/cve/CVE-2020-10673
https://www.cve.org/CVERecord?id=CVE-2020-10673
https://nvd.nist.gov/vuln/detail/CVE-2020-10673
https://access.redhat.com/security/cve/CVE-2020-13936
https://www.cve.org/CVERecord?id=CVE-2020-13936
https://nvd.nist.gov/vuln/detail/CVE-2020-13936
https://access.redhat.com/security/cve/CVE-2021-3717
https://www.cve.org/CVERecord?id=CVE-2021-3717
https://nvd.nist.gov/vuln/detail/CVE-2021-3717
https://access.redhat.com/security/cve/CVE-2021-44228
https://access.redhat.com/security/vulnerabilities/RHSB-2021-009
https://www.cve.org/CVERecord?id=CVE-2021-44228
https://nvd.nist.gov/vuln/detail/CVE-2021-44228
https://github.com/advisories/GHSA-jfh8-c2jp-5v3q
https://logging.apache.org/log4j/2.x/security.html
https://www.lunasec.io/docs/blog/log4j-zero-day/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://access.redhat.com/security/cve/CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
https://nvd.nist.gov/vuln/detail/CVE-2021-45046
https://www.openwall.com/lists/oss-security/2021/12/14/4
https://access.redhat.com/security/cve/CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
https://nvd.nist.gov/vuln/detail/CVE-2022-1471
https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2
https://access.redhat.com/security/cve/CVE-2022-41881
https://www.cve.org/CVERecord?id=CVE-2022-41881
https://nvd.nist.gov/vuln/detail/CVE-2022-41881
https://access.redhat.com/security/cve/CVE-2022-42003
https://www.cve.org/CVERecord?id=CVE-2022-42003
https://nvd.nist.gov/vuln/detail/CVE-2022-42003
https://access.redhat.com/security/cve/CVE-2022-42004
https://www.cve.org/CVERecord?id=CVE-2022-42004
https://nvd.nist.gov/vuln/detail/CVE-2022-42004
https://access.redhat.com/security/cve/CVE-2022-42889
https://www.cve.org/CVERecord?id=CVE-2022-42889
https://nvd.nist.gov/vuln/detail/CVE-2022-42889
https://blogs.apache.org/security/entry/cve-2022-42889
https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om
https://seclists.org/oss-sec/2022/q4/22
https://access.redhat.com/security/cve/CVE-2022-45047
https://www.cve.org/CVERecord?id=CVE-2022-45047
https://nvd.nist.gov/vuln/detail/CVE-2022-45047
https://www.mail-archive.com/dev@mina.apache.org/msg39312.html
https://access.redhat.com/security/cve/CVE-2022-45693
https://www.cve.org/CVERecord?id=CVE-2022-45693
https://nvd.nist.gov/vuln/detail/CVE-2022-45693
https://access.redhat.com/security/cve/CVE-2022-46363
https://www.cve.org/CVERecord?id=CVE-2022-46363
https://nvd.nist.gov/vuln/detail/CVE-2022-46363
https://lists.apache.org/thread/pdzo1qgyplf4y523tnnzrcm7hoco3l8c
Affected packages
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jackson-databind
Package
Name
eap7-jackson-databind
Purl
pkg:rpm/redhat/eap7-jackson-databind
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.8.11.6-2.SP1_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy
Package
Name
eap7-resteasy
Purl
pkg:rpm/redhat/eap7-resteasy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-atom-provider
Package
Name
eap7-resteasy-atom-provider
Purl
pkg:rpm/redhat/eap7-resteasy-atom-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-cdi
Package
Name
eap7-resteasy-cdi
Purl
pkg:rpm/redhat/eap7-resteasy-cdi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-client
Package
Name
eap7-resteasy-client
Purl
pkg:rpm/redhat/eap7-resteasy-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-crypto
Package
Name
eap7-resteasy-crypto
Purl
pkg:rpm/redhat/eap7-resteasy-crypto
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jackson-provider
Package
Name
eap7-resteasy-jackson-provider
Purl
pkg:rpm/redhat/eap7-resteasy-jackson-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jackson2-provider
Package
Name
eap7-resteasy-jackson2-provider
Purl
pkg:rpm/redhat/eap7-resteasy-jackson2-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jaxb-provider
Package
Name
eap7-resteasy-jaxb-provider
Purl
pkg:rpm/redhat/eap7-resteasy-jaxb-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jaxrs
Package
Name
eap7-resteasy-jaxrs
Purl
pkg:rpm/redhat/eap7-resteasy-jaxrs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jettison-provider
Package
Name
eap7-resteasy-jettison-provider
Purl
pkg:rpm/redhat/eap7-resteasy-jettison-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jose-jwt
Package
Name
eap7-resteasy-jose-jwt
Purl
pkg:rpm/redhat/eap7-resteasy-jose-jwt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-jsapi
Package
Name
eap7-resteasy-jsapi
Purl
pkg:rpm/redhat/eap7-resteasy-jsapi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-json-p-provider
Package
Name
eap7-resteasy-json-p-provider
Purl
pkg:rpm/redhat/eap7-resteasy-json-p-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-multipart-provider
Package
Name
eap7-resteasy-multipart-provider
Purl
pkg:rpm/redhat/eap7-resteasy-multipart-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-spring
Package
Name
eap7-resteasy-spring
Purl
pkg:rpm/redhat/eap7-resteasy-spring
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-validator-provider-11
Package
Name
eap7-resteasy-validator-provider-11
Purl
pkg:rpm/redhat/eap7-resteasy-validator-provider-11
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-resteasy-yaml-provider
Package
Name
eap7-resteasy-yaml-provider
Purl
pkg:rpm/redhat/eap7-resteasy-yaml-provider
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.0.27-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-velocity
Package
Name
eap7-velocity
Purl
pkg:rpm/redhat/eap7-velocity
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.0-3.redhat_00006.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly
Package
Name
eap7-wildfly
Purl
pkg:rpm/redhat/eap7-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.9-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-modules
Package
Name
eap7-wildfly-modules
Purl
pkg:rpm/redhat/eap7-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.9-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf
Package
Name
eap7-apache-cxf
Purl
pkg:rpm/redhat/eap7-apache-cxf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-4.redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-rt
Package
Name
eap7-apache-cxf-rt
Purl
pkg:rpm/redhat/eap7-apache-cxf-rt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-4.redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-services
Package
Name
eap7-apache-cxf-services
Purl
pkg:rpm/redhat/eap7-apache-cxf-services
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-4.redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-apache-cxf-tools
Package
Name
eap7-apache-cxf-tools
Purl
pkg:rpm/redhat/eap7-apache-cxf-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.1.16-4.redhat_00003.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jettison
Package
Name
eap7-jettison
Purl
pkg:rpm/redhat/eap7-jettison
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.3.8-2.redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-netty
Package
Name
eap7-netty
Purl
pkg:rpm/redhat/eap7-netty
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.63-1.Final_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-netty-all
Package
Name
eap7-netty-all
Purl
pkg:rpm/redhat/eap7-netty-all
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.1.63-1.Final_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-snakeyaml
Package
Name
eap7-snakeyaml
Purl
pkg:rpm/redhat/eap7-snakeyaml
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.33.0-1.SP1_redhat_00001.1.ep7.el7
RHSA-2025:1746 - OSV