This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.
History

Tue, 08 Jul 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat jboss Enterprise Application Platform
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform

Fri, 20 Jun 2025 12:30:00 +0000


Fri, 20 Jun 2025 12:15:00 +0000

Type Values Removed Values Added
Title Org.jboss.hal-hal-parent: stored cross-site scripting (xss) in jboss eap management console org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities. This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp

Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.
Title org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console Org.jboss.hal-hal-parent: stored cross-site scripting (xss) in jboss eap management console
First Time appeared Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
References

Fri, 28 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: REJECTED

Assigner: redhat

Published:

Updated: 2025-06-20T11:50:40.917Z

Reserved: 2025-03-28T06:08:55.376Z

Link: CVE-2025-2901

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2025-03-28T14:15:22.020

Modified: 2025-06-20T12:15:21.010

Link: CVE-2025-2901

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-28T00:00:00Z

Links: CVE-2025-2901 - Bugzilla