CVE-2020-14297
published 2020-07-24CVE-2020-14297: A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the…
PriorityP430medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.20%
64.8th percentile
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | wildfly | — | — |
| redhat | amq | — | — |
| redhat | jboss-ejb-client | >= 1.0.0 < 4.0.34 | 4.0.34 |
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wildfly EJB Client causes DoS
ghsa·2022-05-24
CVE-2020-14297 [MEDIUM] CWE-400 Wildfly EJB Client causes DoS
Wildfly EJB Client causes DoS
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventually unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
OSV
Wildfly EJB Client causes DoS
osv·2022-05-24
CVE-2020-14297 [MEDIUM] Wildfly EJB Client causes DoS
Wildfly EJB Client causes DoS
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventually unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Red Hat
wildfly: Some EJB transaction objects may get accumulated causing Denial of Service
vendor_redhat·2020-07-23·CVSS 6.5
CVE-2020-14297 [MEDIUM] CWE-400 wildfly: Some EJB transaction objects may get accumulated causing Denial of Service
wildfly: Some EJB transaction objects may get accumulated causing Denial of Service
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
A flaw was found in Wildfly's EJB Client, where the accumulation of specific EJB transaction objects over time can cause services to slow down and eventually become unavailable. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.
Package: jboss-ejb-client (Red Hat BPM Suite 6) - Out of support scope
Package: wil
No detection rules found.
No public exploits indexed.
2020-07-24
Published