Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14297

Опубликовано: 23 июл. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.

A flaw was found in Wildfly's EJB Client, where the accumulation of specific EJB transaction objects over time can cause services to slow down and eventually become unavailable. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jboss-ejb-clientOut of support scope
Red Hat CodeReady Studio 12wildflyNot affected
Red Hat Data Grid 8wildflyNot affected
Red Hat Decision Manager 7jboss-ejb-clientNot affected
Red Hat JBoss Data Grid 7jboss-ejb-clientOut of support scope
Red Hat JBoss Enterprise Application Platform 6jboss-ejb-clientOut of support scope
Red Hat JBoss Enterprise Application Platform Continuous Deliveryjboss-ejb-clientOut of support scope
Red Hat JBoss Fuse 6jboss-ejb-clientOut of support scope
Red Hat JBoss Operations Network 3jboss-ejb-clientOut of support scope
Red Hat OpenShift Application Runtimesjboss-ejb-clientAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1853595wildfly: Some EJB transaction objects may get accumulated causing Denial of Service

EPSS

Процентиль: 59%
0.00384
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.

CVSS3: 6.5
debian
больше 5 лет назад

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat ...

CVSS3: 6.5
github
больше 3 лет назад

Wildfly EJB Client causes DoS

EPSS

Процентиль: 59%
0.00384
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2020-14297