#VU64038 Memory leak in JBoss EJB client for WildFly


Published: 2022-10-19

Vulnerability identifier: #VU64038

Vulnerability risk: Medium

CVSSv3.1: 6.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2022-0853

CWE-ID: CWE-401

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
JBoss EJB client for WildFly
Universal components / Libraries / Libraries used by multiple products

Vendor: Red Hat Inc.

Description
The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak. A remote attacker can force the application to leak memory and perform denial of service attack.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

JBoss EJB client for WildFly: All versions


External links
http://bugzilla.redhat.com/show_bug.cgi?id=2060725
http://github.com/ByteHackr/CVE-2022-0853


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability