Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33455
HistoryDec 27, 2021 - 12:41 a.m.

Denial Of Service (DoS)

2021-12-2700:41:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
jboss
vulnerability
denial of service
ejb server
jboss-remoting code

EPSS

0.001

Percentile

36.9%

jboss is vulnerable to denial of service. The vulnerability exists due to lack of validating the ACK message allowing an attacker to cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the lines that send the ACK message from the EJB client code.

EPSS

0.001

Percentile

36.9%