PT-2020-13963 · Red Hat · Wildfly+1
Published
2020-07-24
·
Updated
2023-12-29
·
CVE-2020-14297
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss EAP 7
Description
A flaw was discovered in Wildfly's EJB Client, where some specific EJB transaction objects may get accumulated over time, causing services to slow down and eventually become unavailable. An attacker can take advantage of this issue to cause a denial of service attack, making services unavailable.
Recommendations
For Red Hat JBoss EAP 7, consider implementing measures to prevent the accumulation of EJB transaction objects, such as regularly cleaning up or optimizing transaction handling, until a patch is available. As a temporary workaround, consider restricting access to services that utilize the EJB Client to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Jboss Eap 7
Wildfly