CVE-2020-25644

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
redhatwildfly_openssl
𝑥
< 1.1.3
redhatdata_grid
8.0
redhatjboss_data_grid
7.0.0
redhatjboss_enterprise_application_platform
7.0.0
redhatjboss_fuse
7.0.0
redhatopenshift_application_runtimes
-
redhatsingle_sign-on
7.0
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappservice_level_manager
-
𝑥
= Vulnerable software versions