jboss is vulnerable to denial of service. The vulnerability exists due to lack of validating the ACK message allowing an attacker to cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the lines that send the ACK message from the EJB client code.
access.redhat.com/documentation/en-us/red_hat_fuse/7.10/
access.redhat.com/errata/RHSA-2021:5134
access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.fuse&version=7.10.0
access.redhat.com/security/updates/classification/#critical
access.redhat.com/security/vulnerabilities/RHSB-2021-009
bugzilla.redhat.com/show_bug.cgi?id=1905796