{"id":"CVE-2025-23367","title":"A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider","summary":"A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can sus…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-284"],"vendor":"redhat","product":"jboss_enterprise_application_platform","affected":["jboss_enterprise_application_platform >= 7.4, < 7.4.21","jboss_enterprise_application_platform >= 8.0.0, < 8.0.7","wildfly < 27.0.1","wildfly = 28.0.0"],"patched":["jboss_enterprise_application_platform 8.0.7","wildfly 27.0.1"],"published":"2025-01-30","updated":"2026-09-18","sourceUpdated":"2026-09-18T00:16:51.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-23367","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3465","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3467","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3989","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3990","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3992","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:4552","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-23367","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2337620","label":"secalert@redhat.com"},{"url":"https://github.com/advisories/GHSA-qr6x-62gq-4ccp","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23367.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-23367"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23367"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-01-30T14:54:55.951787Z"},"epss":0.00774,"epssPercentile":0.53791,"ingestedAt":"2026-08-04T07:38:00.403Z","slug":"CVE-2025-23367","body":"## Overview\n\nA flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. \nThe vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.\n\n## Affected\n\n- `jboss_enterprise_application_platform >= 7.4, < 7.4.21`\n- `jboss_enterprise_application_platform >= 8.0.0, < 8.0.7`\n- `wildfly < 27.0.1`\n- `wildfly = 28.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jboss_enterprise_application_platform 8.0.7`\n- `wildfly 27.0.1`\n\n## Vendor advisories\n\n- **RHSA-2025:3465** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server, Red Hat JBoss EAP 7.4 for RHEL 8, Red Hat JBoss EAP 7.4 for RHEL 9 · released 2025-04-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:3465)\n- **RHSA-2025:3989** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3989)\n- **RHSA-2025:3990** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 9 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3990)\n- **RHSA-2025:3992** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3992)\n- **RHSA-2025:3467** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2025-04-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:3467)\n- **Red Hat VEX** · Moderate · affected: Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23367.json)\n- **RHSA-2025:4552** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.4.22 · released 2025-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2025:4552)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}