Security Advisory

CVE-2020-14307

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-07-24 00:00:00
Last updated 2024-08-04 12:39:36
Assigner redhat
CVSS score 6.5
State PUBLISHED

Description

A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.