CVE-2015-5220
published 2015-10-27CVE-2015-5220: The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.98%
85.7th percentile
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.4.3 | — |
| redhat | jboss_wildfly_application_server | <= 2.0.0 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9g5x-j6wf-xvr6: The Web Console in Red Hat Enterprise Application Platform (EAP) before 6
ghsa_unreviewed·2022-05-17
CVE-2015-5220 [MEDIUM] CWE-119 GHSA-9g5x-j6wf-xvr6: The Web Console in Red Hat Enterprise Application Platform (EAP) before 6
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
Red Hat
OOME from EAP 6 http management console
vendor_redhat·2015-10-15·CVSS 5.0
CVE-2015-5220 [MEDIUM] CWE-770 OOME from EAP 6 http management console
OOME from EAP 6 http management console
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
It was discovered that sending requests containing large headers to the Web Console produced a Java OutOfMemoryError in the HTTP management interface. An attacker could use this flaw to cause a denial of service.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1904.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1905.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1906.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1907.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1908.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1519.htmlhttp://www.securitytracker.com/id/1033859https://bugzilla.redhat.com/show_bug.cgi?id=1255597http://rhn.redhat.com/errata/RHSA-2015-1904.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1905.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1906.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1907.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1908.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1519.htmlhttp://www.securitytracker.com/id/1033859https://bugzilla.redhat.com/show_bug.cgi?id=1255597
2015-10-27
Published