Vulnerability Database
Blog
FAQ
Docs
RHSA-2025:4226
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2025:4226
Import Source
https://security.access.redhat.com/data/osv/RHSA-2025:4226.json
JSON Data
https://api.test.osv.dev/v1/vulns/RHSA-2025:4226
Published
2025-04-28T10:03:38Z
Modified
2025-04-28T10:30:44.391736Z
Upstream
CVE-2023-1108
CVE-2021-40690
CVE-2022-25857
CVE-2022-2053
CVE-2022-40152
CVE-2022-0084
CVE-2024-1635
CVE-2022-25647
CVE-2023-1973
CVE-2023-3223
CVE-2021-37714
CVE-2021-3690
CVE-2022-1319
CVE-2021-3859
CVE-2022-40149
CVE-2022-24785
CVE-2022-23913
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.10 on RHEL 7 security update
Details
References
https://access.redhat.com/errata/RHSA-2025:4226
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
https://bugzilla.redhat.com/show_bug.cgi?id=1991299
https://bugzilla.redhat.com/show_bug.cgi?id=1995259
https://bugzilla.redhat.com/show_bug.cgi?id=2010378
https://bugzilla.redhat.com/show_bug.cgi?id=2011190
https://bugzilla.redhat.com/show_bug.cgi?id=2063601
https://bugzilla.redhat.com/show_bug.cgi?id=2064226
https://bugzilla.redhat.com/show_bug.cgi?id=2072009
https://bugzilla.redhat.com/show_bug.cgi?id=2073890
https://bugzilla.redhat.com/show_bug.cgi?id=2080850
https://bugzilla.redhat.com/show_bug.cgi?id=2095862
https://bugzilla.redhat.com/show_bug.cgi?id=2126789
https://bugzilla.redhat.com/show_bug.cgi?id=2134291
https://bugzilla.redhat.com/show_bug.cgi?id=2135771
https://bugzilla.redhat.com/show_bug.cgi?id=2174246
https://bugzilla.redhat.com/show_bug.cgi?id=2185662
https://bugzilla.redhat.com/show_bug.cgi?id=2209689
https://bugzilla.redhat.com/show_bug.cgi?id=2264928
https://issues.redhat.com/browse/JBEAP-29286
https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4226.json
https://access.redhat.com/security/cve/CVE-2021-3690
https://www.cve.org/CVERecord?id=CVE-2021-3690
https://nvd.nist.gov/vuln/detail/CVE-2021-3690
https://access.redhat.com/security/cve/CVE-2021-3859
https://www.cve.org/CVERecord?id=CVE-2021-3859
https://nvd.nist.gov/vuln/detail/CVE-2021-3859
https://access.redhat.com/security/cve/CVE-2021-37714
https://www.cve.org/CVERecord?id=CVE-2021-37714
https://nvd.nist.gov/vuln/detail/CVE-2021-37714
https://github.com/jhy/jsoup/security/advisories/GHSA-m72m-mhq2-9p6c
https://access.redhat.com/security/cve/CVE-2021-40690
https://www.cve.org/CVERecord?id=CVE-2021-40690
https://nvd.nist.gov/vuln/detail/CVE-2021-40690
https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E
https://access.redhat.com/security/cve/CVE-2022-0084
https://www.cve.org/CVERecord?id=CVE-2022-0084
https://nvd.nist.gov/vuln/detail/CVE-2022-0084
https://access.redhat.com/security/cve/CVE-2022-1319
https://www.cve.org/CVERecord?id=CVE-2022-1319
https://nvd.nist.gov/vuln/detail/CVE-2022-1319
https://access.redhat.com/security/cve/CVE-2022-2053
https://www.cve.org/CVERecord?id=CVE-2022-2053
https://nvd.nist.gov/vuln/detail/CVE-2022-2053
https://access.redhat.com/security/cve/CVE-2022-23913
https://www.cve.org/CVERecord?id=CVE-2022-23913
https://nvd.nist.gov/vuln/detail/CVE-2022-23913
https://lists.apache.org/thread/fjynj57rd99s814rdn5hzvmx8lz403q2
https://access.redhat.com/security/cve/CVE-2022-24785
https://www.cve.org/CVERecord?id=CVE-2022-24785
https://nvd.nist.gov/vuln/detail/CVE-2022-24785
https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4
https://access.redhat.com/security/cve/CVE-2022-25647
https://www.cve.org/CVERecord?id=CVE-2022-25647
https://nvd.nist.gov/vuln/detail/CVE-2022-25647
https://access.redhat.com/security/cve/CVE-2022-25857
https://www.cve.org/CVERecord?id=CVE-2022-25857
https://nvd.nist.gov/vuln/detail/CVE-2022-25857
https://bitbucket.org/snakeyaml/snakeyaml/issues/525
https://access.redhat.com/security/cve/CVE-2022-40149
https://www.cve.org/CVERecord?id=CVE-2022-40149
https://nvd.nist.gov/vuln/detail/CVE-2022-40149
https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.1
https://access.redhat.com/security/cve/CVE-2022-40152
https://www.cve.org/CVERecord?id=CVE-2022-40152
https://nvd.nist.gov/vuln/detail/CVE-2022-40152
https://github.com/advisories/GHSA-3f7h-mf4q-vrm4
https://access.redhat.com/security/cve/CVE-2023-1108
https://www.cve.org/CVERecord?id=CVE-2023-1108
https://nvd.nist.gov/vuln/detail/CVE-2023-1108
https://github.com/advisories/GHSA-m4mm-pg93-fv78
https://access.redhat.com/security/cve/CVE-2023-1973
https://www.cve.org/CVERecord?id=CVE-2023-1973
https://nvd.nist.gov/vuln/detail/CVE-2023-1973
https://access.redhat.com/security/cve/CVE-2023-3223
https://www.cve.org/CVERecord?id=CVE-2023-3223
https://nvd.nist.gov/vuln/detail/CVE-2023-3223
https://access.redhat.com/security/cve/CVE-2024-1635
https://www.cve.org/CVERecord?id=CVE-2024-1635
https://nvd.nist.gov/vuln/detail/CVE-2024-1635
Affected packages
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis
Package
Name
eap7-activemq-artemis
Purl
pkg:rpm/redhat/eap7-activemq-artemis
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-cli
Package
Name
eap7-activemq-artemis-cli
Purl
pkg:rpm/redhat/eap7-activemq-artemis-cli
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-commons
Package
Name
eap7-activemq-artemis-commons
Purl
pkg:rpm/redhat/eap7-activemq-artemis-commons
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-core-client
Package
Name
eap7-activemq-artemis-core-client
Purl
pkg:rpm/redhat/eap7-activemq-artemis-core-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-dto
Package
Name
eap7-activemq-artemis-dto
Purl
pkg:rpm/redhat/eap7-activemq-artemis-dto
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-hornetq-protocol
Package
Name
eap7-activemq-artemis-hornetq-protocol
Purl
pkg:rpm/redhat/eap7-activemq-artemis-hornetq-protocol
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-hqclient-protocol
Package
Name
eap7-activemq-artemis-hqclient-protocol
Purl
pkg:rpm/redhat/eap7-activemq-artemis-hqclient-protocol
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-jdbc-store
Package
Name
eap7-activemq-artemis-jdbc-store
Purl
pkg:rpm/redhat/eap7-activemq-artemis-jdbc-store
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-jms-client
Package
Name
eap7-activemq-artemis-jms-client
Purl
pkg:rpm/redhat/eap7-activemq-artemis-jms-client
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-jms-server
Package
Name
eap7-activemq-artemis-jms-server
Purl
pkg:rpm/redhat/eap7-activemq-artemis-jms-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-journal
Package
Name
eap7-activemq-artemis-journal
Purl
pkg:rpm/redhat/eap7-activemq-artemis-journal
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-native
Package
Name
eap7-activemq-artemis-native
Purl
pkg:rpm/redhat/eap7-activemq-artemis-native
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-ra
Package
Name
eap7-activemq-artemis-ra
Purl
pkg:rpm/redhat/eap7-activemq-artemis-ra
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-selector
Package
Name
eap7-activemq-artemis-selector
Purl
pkg:rpm/redhat/eap7-activemq-artemis-selector
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-server
Package
Name
eap7-activemq-artemis-server
Purl
pkg:rpm/redhat/eap7-activemq-artemis-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-activemq-artemis-service-extensions
Package
Name
eap7-activemq-artemis-service-extensions
Purl
pkg:rpm/redhat/eap7-activemq-artemis-service-extensions
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-artemis-native
Package
Name
eap7-artemis-native
Purl
pkg:rpm/redhat/eap7-artemis-native
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-artemis-native-debuginfo
Package
Name
eap7-artemis-native-debuginfo
Purl
pkg:rpm/redhat/eap7-artemis-native-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-artemis-native-wildfly
Package
Name
eap7-artemis-native-wildfly
Purl
pkg:rpm/redhat/eap7-artemis-native-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:1.5.5.016-1.redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jboss-xnio-base
Package
Name
eap7-jboss-xnio-base
Purl
pkg:rpm/redhat/eap7-jboss-xnio-base
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.5.11-1.Final_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-jsoup
Package
Name
eap7-jsoup
Purl
pkg:rpm/redhat/eap7-jsoup
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.14.2-1.redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-undertow
Package
Name
eap7-undertow
Purl
pkg:rpm/redhat/eap7-undertow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.4.18-14.SP13_redhat_00001.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly
Package
Name
eap7-wildfly
Purl
pkg:rpm/redhat/eap7-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.10-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-wildfly-modules
Package
Name
eap7-wildfly-modules
Purl
pkg:rpm/redhat/eap7-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.1.10-2.GA_redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-woodstox-core
Package
Name
eap7-woodstox-core
Purl
pkg:rpm/redhat/eap7-woodstox-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.3-2.redhat_00002.1.ep7.el7
Red Hat:jboss_enterprise_application_platform_eus:7.1::el7
/
eap7-xml-security
Package
Name
eap7-xml-security
Purl
pkg:rpm/redhat/eap7-xml-security
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.10-2.redhat_00002.1.ep7.el7
RHSA-2025:4226 - OSV