CVE-2025-2251: Red Hat JBoss Enterprise Application Platform 7
Medium severity, CVSS 6.2. EPSS: 1.1% chance of exploitation in the next 30 days.
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object, leading to remote code execution without requiring authentication.
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 8: before 0:2.16.0-21.redhat_00055.1.el8eap (fixed in 0:2.16.0-21.redhat_00055.1.el8eap); before 0:3.5.10-1.redhat_00001.1.el8eap (fixed in 0:3.5.10-1.redhat_00001.1.el8eap); before 1:1.0.2-5.redhat_00004.1.el8eap (fixed in 1:1.0.2-5.redhat_00004.1.el8eap); before 0:1.9.6-1.Final_redhat_00001.1.el8eap (fixed in 0:1.9.6-1.Final_redhat_00001.1.el8eap); before 0:2.3.14-9.SP10_redhat_00001.1.el8eap (fixed in 0:2.3.14-9.SP10_redhat_00001.1.el8eap); before 0:3.3.27-1.Final_redhat_00001.1.el8eap (fixed in 0:3.3.27-1.Final_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 9: before 0:2.16.0-21.redhat_00055.1.el9eap (fixed in 0:2.16.0-21.redhat_00055.1.el9eap); before 0:3.5.10-1.redhat_00001.1.el9eap (fixed in 0:3.5.10-1.redhat_00001.1.el9eap); before 1:1.0.2-5.redhat_00004.1.el9eap (fixed in 1:1.0.2-5.redhat_00004.1.el9eap); before 0:1.9.6-1.Final_redhat_00001.1.el9eap (fixed in 0:1.9.6-1.Final_redhat_00001.1.el9eap); before 0:2.3.14-9.SP10_redhat_00001.1.el9eap (fixed in 0:2.3.14-9.SP10_redhat_00001.1.el9eap); before 0:3.3.27-1.Final_redhat_00001.1.el9eap (fixed in 0:3.3.27-1.Final_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 On Rhel 7: before 0:2.16.0-21.redhat_00055.1.el7eap (fixed in 0:2.16.0-21.redhat_00055.1.el7eap); before 0:3.5.10-1.redhat_00001.1.el7eap (fixed in 0:3.5.10-1.redhat_00001.1.el7eap); before 1:1.0.2-5.redhat_00004.1.el7eap (fixed in 1:1.0.2-5.redhat_00004.1.el7eap); before 0:1.9.6-1.Final_redhat_00001.1.el7eap (fixed in 0:1.9.6-1.Final_redhat_00001.1.el7eap); before 0:2.3.14-9.SP10_redhat_00001.1.el7eap (fixed in 0:2.3.14-9.SP10_redhat_00001.1.el7eap); before 0:3.3.27-1.Final_redhat_00001.1.el7eap (fixed in 0:3.3.27-1.Final_redhat_00001.1.el7eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0.8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:2.33.0-3.redhat_00017.1.el8eap (fixed in 0:2.33.0-3.redhat_00017.1.el8eap); before 0:1.11.0-1.redhat_00001.1.el8eap (fixed in 0:1.11.0-1.redhat_00001.1.el8eap); before 0:4.0.6-2.redhat_00001.1.el8eap (fixed in 0:4.0.6-2.redhat_00001.1.el8eap); before 0:0.8.12-1.redhat_00001.1.el8eap (fixed in 0:0.8.12-1.redhat_00001.1.el8eap); before 0:800.8.0-1.GA_redhat_00001.1.el8eap (fixed in 0:800.8.0-1.GA_redhat_00001.1.el8eap); before 0:4.0.3-1.Final_redhat_00001.1.el8eap (fixed in 0:4.0.3-1.Final_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:2.33.0-3.redhat_00017.1.el9eap (fixed in 0:2.33.0-3.redhat_00017.1.el9eap); before 0:1.11.0-1.redhat_00001.1.el9eap (fixed in 0:1.11.0-1.redhat_00001.1.el9eap); before 0:4.0.6-2.redhat_00001.1.el9eap (fixed in 0:4.0.6-2.redhat_00001.1.el9eap); before 0:0.8.12-1.redhat_00001.1.el9eap (fixed in 0:0.8.12-1.redhat_00001.1.el9eap); before 0:800.8.0-1.GA_redhat_00001.1.el9eap (fixed in 0:800.8.0-1.GA_redhat_00001.1.el9eap); before 0:4.0.3-1.Final_redhat_00001.1.el9eap (fixed in 0:4.0.3-1.Final_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
Published 2025-04-07. Last modified 2026-08-19.