vulnerability
Red Hat JBoss EAP: CVE-2025-11602: Sensitive Information in Resource Not Removed Before Reuse
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Oct 31, 2025 | Nov 7, 2025 | Nov 26, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Oct 31, 2025
Added
Nov 7, 2025
Modified
Nov 26, 2025
Description
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.. A flaw was found in Neo4j. A potential information leak in the bolt protocol handshake allows an attacker to obtain one byte of information from previous connections. However, the attacker has no control over the information leaked in server responses.
Solution
red-hat-jboss-eap-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.