CVE-2025-23367 - CVE House
Back to Database
Status published Medium CVE-2025-23367

Org.wildfly.core:wildfly-server: wildfly improper rbac permission

Vulnerability Description

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23367

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue.

Affected Vendor

Affected Software

Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8, Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, Red Hat Single Sign-On 7
Vulnerable Versions:
0, 28.0.0.Beta1, 0:4.1.119-1.Final_redhat_00004.1.el8eap, 0:7.4.21-3.GA_29548_redhat_00001.1.el8eap, 0:4.1.119-1.Final_redhat_00004.1.el9eap, 0:7.4.21-3.GA_29548_redhat_00001.1.el9eap, 0:4.1.119-1.Final_redhat_00004.1.el7eap, 0:7.4.21-3.GA_29548_redhat_00001.1.el7eap, 0:8.0.7-3.GA_redhat_00004.1.el8eap, 0:8.0.7-3.GA_redhat_00004.1.el9eap

Timeline

Official Publish: January 30th, 2025
Last Modified: April 30th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)