cve/2020/CVE-2020-14307.md
2024-05-25 21:48:12 +02:00

948 B

CVE-2020-14307

Description

A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unavailable.

POC

Reference

No PoCs from references.

Github