CVE-2020-25644
HIGHRedhat Wildfly Openssl < 1.1.3 - Memory Leak
Title source: ruleDescription
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
References (4)
Scores
CVSS v3
7.5
EPSS
0.0046
EPSS Percentile
64.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (11)
redhat/wildfly_openssl
< 1.1.3
redhat/data_grid
redhat/jboss_data_grid
redhat/jboss_enterprise_application_platform
redhat/jboss_fuse
redhat/openshift_application_runtimes
redhat/single_sign-on
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/service_level_manager
org.wildfly.openssl/wildfly-openssl-natives-parent
< 1.1.3.FinalMaven
Timeline
Published
Oct 06, 2020
Tracked Since
Feb 18, 2026