← back
CVE-2020-14297

CVE-2020-14297

CVSS 6.5 MEDIUMEPSS 1.2%CWE-400
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
24 Jul 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Red Hat · wildfly

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →