Bug 1853595 (CVE-2020-14297) - CVE-2020-14297 wildfly: Some EJB transaction objects may get accumulated causing Denial of Service
Summary: CVE-2020-14297 wildfly: Some EJB transaction objects may get accumulated caus...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-14297
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1853551
TreeView+ depends on / blocked
 
Reported: 2020-07-03 09:11 UTC by Kunjan Rathod
Modified: 2021-08-11 18:23 UTC (History)
68 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Wildfly's EJB Client, where the accumulation of specific EJB transaction objects over time can cause services to slow down and eventually become unavailable. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.
Clone Of:
Environment:
Last Closed: 2020-07-24 01:27:48 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2020:3141 0 None None None 2020-07-23 20:32:32 UTC
Red Hat Product Errata RHSA-2020:3142 0 None None None 2020-07-23 20:36:26 UTC
Red Hat Product Errata RHSA-2020:3143 0 None None None 2020-07-23 20:20:53 UTC
Red Hat Product Errata RHSA-2020:3144 0 None None None 2020-07-23 20:21:11 UTC
Red Hat Product Errata RHSA-2020:3461 0 None None None 2020-08-17 13:28:56 UTC
Red Hat Product Errata RHSA-2020:3462 0 None None None 2020-08-17 13:31:10 UTC
Red Hat Product Errata RHSA-2020:3463 0 None None None 2020-08-17 13:34:41 UTC
Red Hat Product Errata RHSA-2020:3464 0 None None None 2020-08-17 13:26:47 UTC
Red Hat Product Errata RHSA-2020:3539 0 None None None 2020-09-02 09:48:21 UTC
Red Hat Product Errata RHSA-2020:3637 0 None None None 2020-09-07 12:57:14 UTC
Red Hat Product Errata RHSA-2020:3638 0 None None None 2020-09-07 13:03:27 UTC
Red Hat Product Errata RHSA-2020:3639 0 None None None 2020-09-07 13:00:12 UTC
Red Hat Product Errata RHSA-2020:3642 0 None None None 2020-09-07 13:08:30 UTC
Red Hat Product Errata RHSA-2020:3817 0 None None None 2020-09-23 09:01:06 UTC
Red Hat Product Errata RHSA-2021:3140 0 None None None 2021-08-11 18:23:25 UTC

Description Kunjan Rathod 2020-07-03 09:11:56 UTC
A vulnerability was found in Wildfly's EJB Client, where accumulation of some specific EJB transaction objects in InvocationTracker may lead to DoS.

Comment 8 errata-xmlrpc 2020-07-23 20:20:49 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:3143 https://access.redhat.com/errata/RHSA-2020:3143

Comment 9 errata-xmlrpc 2020-07-23 20:21:07 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:3144 https://access.redhat.com/errata/RHSA-2020:3144

Comment 10 errata-xmlrpc 2020-07-23 20:32:28 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6
  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8

Via RHSA-2020:3141 https://access.redhat.com/errata/RHSA-2020:3141

Comment 11 errata-xmlrpc 2020-07-23 20:36:22 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6
  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8

Via RHSA-2020:3142 https://access.redhat.com/errata/RHSA-2020:3142

Comment 12 Product Security DevOps Team 2020-07-24 01:27:48 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-14297

Comment 13 Product Security DevOps Team 2020-07-24 07:27:45 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-14297

Comment 14 errata-xmlrpc 2020-08-17 13:26:43 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:3464 https://access.redhat.com/errata/RHSA-2020:3464

Comment 15 errata-xmlrpc 2020-08-17 13:28:52 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6

Via RHSA-2020:3461 https://access.redhat.com/errata/RHSA-2020:3461

Comment 16 errata-xmlrpc 2020-08-17 13:31:05 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7

Via RHSA-2020:3462 https://access.redhat.com/errata/RHSA-2020:3462

Comment 17 errata-xmlrpc 2020-08-17 13:34:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8

Via RHSA-2020:3463 https://access.redhat.com/errata/RHSA-2020:3463

Comment 18 errata-xmlrpc 2020-09-02 09:48:11 UTC
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes

Via RHSA-2020:3539 https://access.redhat.com/errata/RHSA-2020:3539

Comment 19 errata-xmlrpc 2020-09-07 12:57:09 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6

Via RHSA-2020:3637 https://access.redhat.com/errata/RHSA-2020:3637

Comment 20 errata-xmlrpc 2020-09-07 13:00:07 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8

Via RHSA-2020:3639 https://access.redhat.com/errata/RHSA-2020:3639

Comment 21 errata-xmlrpc 2020-09-07 13:03:21 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7

Via RHSA-2020:3638 https://access.redhat.com/errata/RHSA-2020:3638

Comment 22 errata-xmlrpc 2020-09-07 13:08:24 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:3642 https://access.redhat.com/errata/RHSA-2020:3642

Comment 24 errata-xmlrpc 2020-09-23 09:00:58 UTC
This issue has been addressed in the following products:

  AMQ Clients 2.y for RHEL 6
  AMQ Clients 2.y for RHEL 8
  AMQ Clients 2.y for RHEL 7

Via RHSA-2020:3817 https://access.redhat.com/errata/RHSA-2020:3817

Comment 27 errata-xmlrpc 2021-08-11 18:23:20 UTC
This issue has been addressed in the following products:

  Red Hat Fuse 7.9

Via RHSA-2021:3140 https://access.redhat.com/errata/RHSA-2021:3140


Note You need to log in before you can comment on or make changes to this bug.