Red Hat JBoss Enterprise Application Platform 7.4.25 vulnerability

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

Published 11 Aug 2026Updated 17 Sep 20264 sources
CVSS 8.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.