cbcvebase.
CVE-2020-14297
published 2020-07-24

CVE-2020-14297: A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the…

PriorityP430medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.20%
64.8th percentile
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.

Affected

5 ranges
VendorProductVersion rangeFixed in
red_hatwildfly
redhatamq
redhatjboss-ejb-client>= 1.0.0 < 4.0.344.0.34
redhatjboss_fuse
redhatsingle_sign-on

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.