PT-2020-13968 · Red Hat · Red Hat Jboss Eap
Published
2020-07-24
·
Updated
2023-02-12
·
CVE-2020-14307
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss EAP 7
Description
A flaw was found in Wildfly's Enterprise Java Beans (EJB) where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received. This allows an attacker to craft a denial of service attack, making the service unavailable.
Recommendations
For Red Hat JBoss EAP 7, consider implementing measures to prevent abuse of the InvocationTracker, such as restricting access to the EJB Client, until a patch is available.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Jboss Eap