SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-14297

An attacker can take advantage and cause denial of service attack and make services unavailable.

MEDIUM 6.5EPSS 1.20%

Does this matter?

Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
1.20% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
redhat/amq · redhat/jboss-ejb-client · redhat/jboss enterprise application platform continuous delivery · redhat/jboss fuse · redhat/openshift application runtimes · redhat/single sign-on
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.