Описание
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB), where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | jboss-ejb-client | Out of support scope | ||
| Red Hat CodeReady Studio 12 | wildfly | Not affected | ||
| Red Hat Data Grid 8 | wildfly | Not affected | ||
| Red Hat Decision Manager 7 | jboss-ejb-client | Not affected | ||
| Red Hat Fuse 7 | jboss-ejb-client | Will not fix | ||
| Red Hat JBoss Data Grid 7 | jboss-ejb-client | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6 | jboss-ejb-client | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | jboss-ejb-client | Out of support scope | ||
| Red Hat JBoss Fuse 6 | jboss-ejb-client | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | jboss-ejb-client | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) ver ...
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.
EPSS
6.5 Medium
CVSS3