<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:06:10 +0000</lastBuildDate>
    <item>
      <title>BIT-wildfly-2025-23367 — Org.wildfly.core:wildfly-server: wildfly improper rbac permission</title>
      <link>https://cve.radiocsirt.org/vuln/bit-wildfly-2025-23367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wildfly&lt;/p&gt;
&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wildfly&lt;/p&gt;
&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-wildfly-2025-23367</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0671 — De multiples vulnérabilités ont été découvertes dans les produits NetApp. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0671</link>
      <description>certfr-2026-avi-0671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0671</guid>
    </item>
    <item>
      <title>EUVD-2026-371663</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371663</link>
      <description>EUVD-2026-371663</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371663</guid>
    </item>
    <item>
      <title>fkie_cve-2025-23367</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23367</link>
      <description>&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-23367</guid>
    </item>
    <item>
      <title>GHSA-qr6x-62gq-4ccp — WildFly improper RBAC permission</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qr6x-62gq-4ccp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.wildfly.core:wildfly-server&lt;/p&gt;
&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;
&lt;p&gt;### Impact
Standalone server (Domain mode is not affected) with use access control enabled with RBAC provider can be suspended or resumed by unauthorized users. When a server is suspended, the server will stop receiving user requests. The resume handle does the opposite; it will cause a suspended server to start accepting user requests.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in [WildFly Core 27.0.1.Final](https://github.com/wildfly/wildfly-core/releases/tag/27.0.1.Final)&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround available&lt;/p&gt;
&lt;p&gt;### References
See also: https://issues.redhat.com/browse/WFCORE-7153&lt;/p&gt;
&lt;p&gt;### Acknowledgements
The WildFly project would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue. https://www.gruppotim.it/it/footer/red-team.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.wildfly.core:wildfly-server&lt;/p&gt;
&lt;p&gt;A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.&lt;/p&gt;
&lt;p&gt;### Impact
Standalone server (Domain mode is not affected) with use access control enabled with RBAC provider can be suspended or resumed by unauthorized users. When a server is suspended, the server will stop receiving user requests. The resume handle does the opposite; it will cause a suspended server to start accepting user requests.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in [WildFly Core 27.0.1.Final](https://github.com/wildfly/wildfly-core/releases/tag/27.0.1.Final)&lt;/p&gt;
&lt;p&gt;### Workarounds
No workaround available&lt;/p&gt;
&lt;p&gt;### References
See also: https://issues.redhat.com/browse/WFCORE-7153&lt;/p&gt;
&lt;p&gt;### Acknowledgements
The WildFly project would like to thank Claudia Bartolini (TIM S.p.A), Marco Ventura (TIM S.p.A), and Massimiliano Brolli (TIM S.p.A) for reporting this issue. https://www.gruppotim.it/it/footer/red-team.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qr6x-62gq-4ccp</guid>
    </item>
    <item>
      <title>RHSA-2025:3465 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.21 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:3465</link>
      <description>&lt;p&gt;netty: Denial of Service attack on windows app using Netty hornetq-core-client: Arbitrarily overwrite files or access sensitive information org.wildfly.core:wildfly-server: Wildfly improper RBAC permission io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: Denial of Service attack on windows app using Netty hornetq-core-client: Arbitrarily overwrite files or access sensitive information org.wildfly.core:wildfly-server: Wildfly improper RBAC permission io.netty:netty-handler: SslHandler doesn&amp;#39;t correctly validate packets which can lead to native crash when using native SSLEngine netty: Denial of Service attack on windows app using Netty commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum&amp;#39;s declaredClass property by default com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:3465</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0230 — Red Hat WildFly: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0230</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat WildFly ausnutzen, um einen Denial of Service herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat WildFly ausnutzen, um einen Denial of Service herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0230</guid>
    </item>
  </channel>
</rss>
