Severity
5.0MEDIUM
EPSS
1.5%
top 18.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 17

Description

The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9g5x-j6wf-xvr6: The Web Console in Red Hat Enterprise Application Platform (EAP) before 62022-05-17
CVEList
CVE-2015-5220: The Web Console in Red Hat Enterprise Application Platform (EAP) before 62015-10-27

📋Vendor Advisories

1
Red Hat
OOME from EAP 6 http management console2015-10-15

💬Community

1
Bugzilla
CVE-2015-5220 OOME from EAP 6 http management console2015-08-21
CVE-2015-5220 (MEDIUM CVSS 5) | The Web Console in Red Hat Enterpri | cvebase.io