CVE-2020-14297

EUVD-2022-4947
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
redhatCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
redhatamq
2.0
redhatjboss-ejb-client
1.0.0 ≤
𝑥
< 4.0.34
redhatjboss_enterprise_application_platform_continuous_delivery
-
redhatjboss_fuse
6.0.0
redhatopenshift_application_runtimes
-
redhatsingle_sign-on
7.0
𝑥
= Vulnerable software versions