CVE Feed

    Dashboard / CVE / CVE-2025-23366

    CVE-2025-23366

    A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

    Published:Jan 14, 2025
    Last Modified:Aug 19, 2026
    EPS:Jan 14, 2025
    EPSS Score:0.00439
    CVSS Score:6.5

    Affected Products

    Vendor
    Redhat
    Product
    Hal Management Console
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jbosseapxp

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High