CVE-2020-25644

HIGH

Redhat Wildfly Openssl < 1.1.3 - Memory Leak

Title source: rule

Description

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

Scores

CVSS v3 7.5
EPSS 0.0046
EPSS Percentile 64.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401
Status published

Affected Products (11)

redhat/wildfly_openssl < 1.1.3
redhat/data_grid
redhat/jboss_data_grid
redhat/jboss_enterprise_application_platform
redhat/jboss_fuse
redhat/openshift_application_runtimes
redhat/single_sign-on
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/service_level_manager
org.wildfly.openssl/wildfly-openssl-natives-parent < 1.1.3.FinalMaven

Timeline

Published Oct 06, 2020
Tracked Since Feb 18, 2026