REDHAT-BUG-2483131: High severity JBoss JBoss EAP vulnerability
original reported in: https://docs.google.com/document/d/1Rf4NtLudECimDNy8F9clUblm6Avx8yF/edit
Remote Class Loading — openjdk-orb JDKBridge honours CDR codebase URL under -secmgr (pre-auth :3528) (JBoss EAP)
Pre-auth remote class loading via IIOP: when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. findings/jboss-eap44.md
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2483131?
The severity of REDHAT-BUG-2483131 is high, rated at 7.
What is REDHAT-BUG-2483131 about?
REDHAT-BUG-2483131 involves a vulnerability in JBoss EAP that allows pre-auth remote class loading via IIOP when using -secmgr.
How do I fix REDHAT-BUG-2483131?
To fix REDHAT-BUG-2483131, JBoss EAP should be updated to a patched version that addresses this remote class loading vulnerability.
Who is affected by REDHAT-BUG-2483131?
REDHAT-BUG-2483131 affects users of JBoss EAP running with the -secmgr option enabled.
When was REDHAT-BUG-2483131 published?
REDHAT-BUG-2483131 was published on May 29, 2026.