Product overview
Red Hat JBoss Enterprise Application Platform is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Networked or application service delivery
- Administrative and operational interfaces
- Versioned maintenance and security updates
Typical use
Used to provide application, infrastructure or operational services to other systems and users.
Deployment
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Red Hat JBoss Enterprise Application Platform |
|---|
| Release | Product policy |
|---|
| End of Support | 1 July 2025 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 1 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Red Hat JBoss Authentication Bypass Vulnerability
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Red Hat · JBossRansomware use: Known
CISA entry ↗
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYManual
Red Hat JBoss Enterprise Application Platform official lifecycle source
Extended Life support is provided according to the published Scope of Coverage and Service Level Agreement. Unlike our Full Support and Maintenance Support phases, this support phase requires an ELS subscription in addition to a supported product’s base subscription. Extended Life Support subscriptions of Red Hat Application Services products provide decreasing support and maintenance over time as described below. | Note that ELS should be purchased prior to the start date of the ELS period (e.g.: July 1, 2025, for JBoss EAP 7). Otherwise, the ELS Add-On subscription must be back-dated to that start date. | Troubleshooting for Application Services product releases in the ELS Life Cycle Phase is limited to the latest minor release. | Container distributions of Application Services products in the ELS Life Cycle Phase will be marked "Deprecated" in the Red Hat Container Catalog. See the article Deprecation of Red Hat Runtimes product container images in the Red Hat Container Catalog for more detail. | ELS-1: | Compare Life Cycle Phases | ELS-1 delivers Critical impact security fixes and selected urgent-priority bug fixes, if and when available. Customers may request specific security or bug fixes and are encouraged to continue applying patch releases. ELS-1 is generally available for 3 years following the end of Maintenance Support.
Publisher identity used by product-specific official-source collectors.
First collected 30 Aug 2026 · Last collected 30 Aug 2026 · Review state accepted
Open official vendor source ↗