Metrics
Affected Vendors & Products
Tue, 08 Jul 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform |
|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9 |
|
Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform |
Fri, 20 Jun 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 20 Jun 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Org.jboss.hal-hal-parent: stored cross-site scripting (xss) in jboss eap management console | org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console |
Metrics |
ssvc
|
Fri, 20 Jun 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities. | This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234. |
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp |
|
Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp |
Fri, 28 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 28 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities. |
Title | org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console | Org.jboss.hal-hal-parent: stored cross-site scripting (xss) in jboss eap management console |
First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp |
|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp |
|
Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp |
|
References |
|
Fri, 28 Mar 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | No description is available for this CVE. | |
Title | org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: REJECTED
Assigner: redhat
Published:
Updated: 2025-06-20T11:50:40.917Z
Reserved: 2025-03-28T06:08:55.376Z
Link: CVE-2025-2901

Updated:

Status : Rejected
Published: 2025-03-28T14:15:22.020
Modified: 2025-06-20T12:15:21.010
Link: CVE-2025-2901
