ZeroHour

CVE-2020-25644

CVSS 3.1
7.5 high
EPSS
2%p83
Published
()
Modified
Description

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

Vendors
redhatnetapp
Products
wildfly openssl, data grid, jboss data grid, jboss enterprise application platform, jboss fuse, openshift application runtimes, single sign-on, oncommand insight, oncommand workflow automation, service level manager
Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.