---
id: CVE-2025-23367
title: >-
  A flaw was found in the Wildfly Server Role Based Access Control (RBAC)
  provider
summary: >-
  A flaw was found in the Wildfly Server Role Based Access Control (RBAC)
  provider. When authorization to control management operations is secured using
  the Role Based Access Control provider, a user without the required privileges
  can sus…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-284
vendor: redhat
product: jboss_enterprise_application_platform
affected:
  - 'jboss_enterprise_application_platform >= 7.4, < 7.4.21'
  - 'jboss_enterprise_application_platform >= 8.0.0, < 8.0.7'
  - wildfly < 27.0.1
  - wildfly = 28.0.0
patched:
  - jboss_enterprise_application_platform 8.0.7
  - wildfly 27.0.1
published: '2025-01-30'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T00:16:51.783'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23367'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:3465'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3467'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3989'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3990'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3992'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:4552'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-23367'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2337620'
    label: secalert@redhat.com
  - url: 'https://github.com/advisories/GHSA-qr6x-62gq-4ccp'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23367.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-23367'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23367'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-01-30T14:54:55.951787Z'
epss: 0.00774
epssPercentile: 0.54252
ingestedAt: '2026-08-04T07:38:00.403Z'
---

## Overview

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. 
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.

## Affected

- `jboss_enterprise_application_platform >= 7.4, < 7.4.21`
- `jboss_enterprise_application_platform >= 8.0.0, < 8.0.7`
- `wildfly < 27.0.1`
- `wildfly = 28.0.0`

## Remediation

Upgrade past the affected range:

- `jboss_enterprise_application_platform 8.0.7`
- `wildfly 27.0.1`

## Vendor advisories

- **RHSA-2025:3465** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server, Red Hat JBoss EAP 7.4 for RHEL 8, Red Hat JBoss EAP 7.4 for RHEL 9 · released 2025-04-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:3465)
- **RHSA-2025:3989** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3989)
- **RHSA-2025:3990** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 9 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3990)
- **RHSA-2025:3992** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2025-04-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:3992)
- **RHSA-2025:3467** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2025-04-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:3467)
- **Red Hat VEX** · Moderate · affected: Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-23367.json)
- **RHSA-2025:4552** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.4.22 · released 2025-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2025:4552)
