Description

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

INFO

Published Date :

2025-01-14T17:41:43.092Z

Last Modified :

2026-04-01T13:31:13.851Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23366 vulnerability.

Vendors Products
Redhat
  • Hal Management Console
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jbosseapxp

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact