Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15562

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8jboss-remotingAffected
Red Hat JBoss Enterprise Application Platform Expansion Packjboss-remotingNot affected
Red Hat JBoss Enterprise Application Platform 7.4.25jboss-remotingFixedRHSA-2026:5380611.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-activemq-artemisFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-glassfish-jsfFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-ironjacamarFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-annotationsFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-coreFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-databindFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-jaxrs-providersFixedRHSA-2026:5364411.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2483135jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service

EPSS

Процентиль: 37%
0.00441
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
7 дней назад

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

CVSS3: 7.5
github
7 дней назад

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

EPSS

Процентиль: 37%
0.00441
Низкий

7.5 High

CVSS3