CVE-2025-12799: Red Hat JBoss Enterprise Application Platform 7
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling.
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1.7.ga: before 2.2.9.SP1-redhat-00001 (fixed in 2.2.9.SP1-redhat-00001)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 10: before 0:1-9.el10eap (fixed in 0:1-9.el10eap); before 0:2.40.0-7.redhat_00015.1.el10eap (fixed in 0:2.40.0-7.redhat_00015.1.el10eap); before 1:2.0.0-2.redhat_00005.1.el10eap (fixed in 1:2.0.0-2.redhat_00005.1.el10eap); before 0:1.8.0-2.redhat_00001.1.el10eap (fixed in 0:1.8.0-2.redhat_00001.1.el10eap); before 0:2.4.0-1.redhat_00002.1.el10eap (fixed in 0:2.4.0-1.redhat_00002.1.el10eap); before 0:2.3.0-1.redhat_00001.1.el10eap (fixed in 0:2.3.0-1.redhat_00001.1.el10eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 8: before 0:4.0.10-3.redhat_00001.1.el8eap (fixed in 0:4.0.10-3.redhat_00001.1.el8eap); before 0:2.0.4-1.Final_redhat_00001.1.el8eap (fixed in 0:2.0.4-1.Final_redhat_00001.1.el8eap); before 0:801.7.0-1.GA_redhat_00001.1.el8eap (fixed in 0:801.7.0-1.GA_redhat_00001.1.el8eap); before 0:6.6.50-1.Final_redhat_00001.1.el8eap (fixed in 0:6.6.50-1.Final_redhat_00001.1.el8eap); before 0:7.3.8-1.Final_redhat_00001.1.el8eap (fixed in 0:7.3.8-1.Final_redhat_00001.1.el8eap); before 1:5.3.23-1.Final_redhat_00001.1.el8eap (fixed in 1:5.3.23-1.Final_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 9: before 0:4.0.10-3.redhat_00001.1.el9eap (fixed in 0:4.0.10-3.redhat_00001.1.el9eap); before 0:2.0.4-1.Final_redhat_00001.1.el9eap (fixed in 0:2.0.4-1.Final_redhat_00001.1.el9eap); before 0:801.7.0-1.GA_redhat_00001.1.el9eap (fixed in 0:801.7.0-1.GA_redhat_00001.1.el9eap); before 0:6.6.50-1.Final_redhat_00001.1.el9eap (fixed in 0:6.6.50-1.Final_redhat_00001.1.el9eap); before 0:7.3.8-1.Final_redhat_00001.1.el9eap (fixed in 0:7.3.8-1.Final_redhat_00001.1.el9eap); before 1:5.3.23-1.Final_redhat_00001.1.el9eap (fixed in 1:5.3.23-1.Final_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Single Sign-On 7
Published 2026-07-07. Last modified 2026-09-29.