CVE-2020-1710

MEDIUM

JBoss EAP 6.4.21 - HTTP Request Parsing Issue

Title source: llm
STIX 2.1

Description

The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1793970

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (9)
redhat/jboss_data_grid
redhat/jboss_data_grid 7.0.0
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform 6.4.21
redhat/jboss_enterprise_application_platform 7.0.0
redhat/jboss_enterprise_application_platform 7.2.0
redhat/jboss_enterprise_application_platform 7.3.0
redhat/openshift_application_runtimes
redhat/single_sign-on
Published Sep 16, 2020
Tracked Since Feb 18, 2026