A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.
History

Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.
Title org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console Org.jboss.hal-hal-parent: stored cross-site scripting (xss) in jboss eap management console
First Time appeared Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
References

Fri, 28 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-04-01T05:07:39.171Z

Reserved: 2025-03-28T06:08:55.376Z

Link: CVE-2025-2901

cve-icon Vulnrichment

Updated: 2025-03-28T14:30:31.139Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T14:15:22.020

Modified: 2025-03-28T18:11:40.180

Link: CVE-2025-2901

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-28T00:00:00Z

Links: CVE-2025-2901 - Bugzilla