PublicCVE

CVE-2020-14307

MEDIUM6.5JSON exportCreate alert

Description

A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected products

  • Red Hat / wildflyjboss-ejb-client versions shipped with Red Hat JBoss EAP 7 – jboss-ejb-client versions shipped with Red Hat JBoss EAP 7