cbcvebase.
CVE-2020-25644
published 2020-10-06

CVE-2020-25644: A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM…

PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.18%
80.4th percentile
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

Affected

6 ranges
VendorProductVersion rangeFixed in
redhatdata_grid
redhatjboss_data_grid
redhatjboss_enterprise_application_platform
redhatjboss_fuse
redhatsingle_sign-on
redhatwildfly_openssl< 1.1.31.1.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.