CVE-2022-0853

CWE-401Memory Leak4 documents4 sources
Severity
7.5HIGH
EPSS
1.3%
top 20.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateMar 12

Description

A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-f67w-c9w2-5v69: A flaw was found in JBoss-client2022-03-12
CVEList
CVE-2022-0853: A flaw was found in JBoss-client2022-03-11

📋Vendor Advisories

1
Red Hat
jboss-client: memory leakage in remote client transaction2022-03-04