CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
AI Score
Confidence
High
EPSS
Percentile
89.5%
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
Vendor | Product | Version | CPE |
---|---|---|---|
redhat | jboss_enterprise_application_platform | * | cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:* |
redhat | jboss_wildfly_application_server | * | cpe:2.3:a:redhat:jboss_wildfly_application_server:*:cr8:*:*:*:*:*:* |
rhn.redhat.com/errata/RHSA-2015-1904.html
rhn.redhat.com/errata/RHSA-2015-1905.html
rhn.redhat.com/errata/RHSA-2015-1906.html
rhn.redhat.com/errata/RHSA-2015-1907.html
rhn.redhat.com/errata/RHSA-2015-1908.html
rhn.redhat.com/errata/RHSA-2016-1519.html
www.securitytracker.com/id/1033859
bugzilla.redhat.com/show_bug.cgi?id=1255597