CVE-2025-2251 - wildfly-ejb3: Improper Deserialization in JBoss Marshalling Allows Remote Code Execution
Updated -
This CVE-2025-2251 is rated Moderate and will be fixed in an upcoming JBoss EAP 8.0 Update & JBoss EAP 7.4 Update.
Poisoned data can be serialized and sent to a remote EJB resulting in potential remote code execution (RCE). The server, via JBoss Marshalling, will deserialize the data and execute a JNDI lookup on a na...
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.