Impact
A flaw in EAP's Elytron permits parameter injection because OAuth2 introspection requests are not properly URL encoded. This oversight allows an attacker to manipulate the token validation process, potentially forging authentication and gaining unauthorized access. The weakness maps to CWE-290, improper authentication.
Affected Systems
Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, and the Red Hat JBoss Enterprise Application Platform Expansion Pack. No specific sub‑versions were listed, so any deployment of these products that uses an Elytron token‑realm with OAuth2 introspection may be vulnerable.
Risk and Exploitability
The CVSS score of 4.2 indicates low to moderate severity; the EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, requiring an attacker to send crafted HTTP requests to a vulnerable EAP application. Because authentication parameters are not encoded, the attacker could alter the introspection query to bypass token validation, creating a risk of unauthorized access. Overall risk is low, but remediation remains advisable.
OpenCVE Enrichment