We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A flaw was found in the JBoss EAP Management Console, where a stored Cross-site scripting vulnerability occurs when an application improperly sanitizes user input before storing it in a data store. When this stored data is later included in web pages without adequate sanitization, malicious scripts can execute in the context of users who view these pages, leading to potential data theft, session hijacking, or other malicious activities.
Reserved 2025-03-28 | Published 2025-03-28 | Updated 2025-04-30 | Assigner redhatImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
2025-03-28: | Reported to Red Hat. |
2025-03-28: | Made public. |
Red Hat would like to thank Łukasz Rupala (ING Hubs Poland) for reporting this issue.
access.redhat.com/security/cve/CVE-2025-2901
bugzilla.redhat.com/show_bug.cgi?id=2355685 (RHBZ#2355685)
Support options