CVE Vulnerabilities

CVE-2020-14384

Uncontrolled Resource Consumption

Published: Sep 09, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat6.0.0 (including)6.0.0 (including)
JbosswebRedhat*7.5.31.final-redhat-3 (excluding)
EAP 6.4.24 releaseRedHat*
Red Hat JBoss Enterprise Application Platform 6.4RedHatjbossweb*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5RedHatjbossweb-0:7.5.31-3.Final_redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossweb-0:7.5.31-3.Final_redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossweb-0:7.5.31-3.Final_redhat_3.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-appclient-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-bundles-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-cli-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-client-all-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-clustering-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-cmp-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-connector-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-controller-client-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-core-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-core-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-deployment-repository-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-deployment-scanner-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-domain-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-domain-http-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-domain-management-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ee-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ee-deployment-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-ejb3-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-embedded-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-host-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jacorb-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-javadocs-0:7.5.24-1.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jaxr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jaxrs-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jdr-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jpa-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jsf-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-jsr77-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-logging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-mail-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-management-client-content-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-messaging-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-modcluster-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-modules-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-naming-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-network-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-configadmin-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-osgi-service-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-picketlink-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-platform-mbean-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-pojo-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-process-controller-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-product-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-protocol-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-remoting-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-sar-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-security-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-server-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-standalone-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-system-jmx-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-threads-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-transactions-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-version-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-web-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-webservices-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossas-welcome-content-eap-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-weld-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjboss-as-xts-0:7.5.24-2.Final_redhat_00001.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossts-1:4.17.45-2.Final_redhat_2.1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbossweb-0:7.5.32-2.Final_redhat_1.2.ep6.el7*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References