PT-2020-13963 · Red Hat · Wildfly+1

Published

2020-07-24

·

Updated

2023-12-29

·

CVE-2020-14297

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Red Hat JBoss EAP 7
Description A flaw was discovered in Wildfly's EJB Client, where some specific EJB transaction objects may get accumulated over time, causing services to slow down and eventually become unavailable. An attacker can take advantage of this issue to cause a denial of service attack, making services unavailable.
Recommendations For Red Hat JBoss EAP 7, consider implementing measures to prevent the accumulation of EJB transaction objects, such as regularly cleaning up or optimizing transaction handling, until a patch is available. As a temporary workaround, consider restricting access to services that utilize the EJB Client to minimize the risk of exploitation.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2020-14297
GHSA-QCCH-9268-59JW
RHSA-2020:3141
RHSA-2020:3142
RHSA-2020:3461
RHSA-2020:3462
RHSA-2020:3463
RHSA-2020:3637
RHSA-2020:3638
RHSA-2020:3639
RHSA-2020:3817

Affected Products

Red Hat Jboss Eap 7
Wildfly