CVE-2020-14297
Last modified
CVE-2020-14297 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Amq | 2.0 |
| Redhat | Jboss-Ejb-Client | >= 1.0.0, < 4.0.34 |
| Redhat | Jboss Enterprise Application Platform Continuous Delivery | All versions |
| Redhat | Jboss Fuse | 6.0.0 |
| Redhat | Openshift Application Runtimes | All versions |
| Redhat | Single Sign-On | 7.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14297Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14297Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14297?
How severe is CVE-2020-14297?
How do I fix CVE-2020-14297?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1429An elevation of privilege vulnerability exists when Windows …7.8
- CVE-2020-14292In the COVIDSafe application through 1.0.21 for Android, uns…5.7
- CVE-2020-14293conf_datetime in Secudos DOMOS 5.8 allows remote attackers t…7.5
- CVE-2020-14294An issue was discovered in Secudos Qiata FTA 1.70.19. The co…6.1
- CVE-2020-14295A SQL injection issue in color.php in Cacti 1.2.12 allows an…7.2
- CVE-2020-14296Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side R…7.1
- CVE-2020-14298The version of docker as released for Red Hat Enterprise Lin…8.8
- CVE-2020-14299A flaw was found in JBoss EAP, where the authentication conf…6.5
- CVE-2020-1430An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-14300The docker packages version docker-1.13.1-108.git4ef4b30.el7…8.8
- CVE-2020-14301An information disclosure vulnerability was found in libvirt…6.5
- CVE-2020-14302A flaw was found in Keycloak before 13.0.0 where an external…4.9
Are you affected by CVE-2020-14297?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
