CERT-In Vulnerability Note
CIVN-2023-0080
Denial of service vulnerability in Red Hat JBoss Enterprise Application
Original Issue Date:March 16, 2023
Severity Rating: HIGH
Software Affected
- JBoss Enterprise Application Platform 7.4 for RHEL 9 x86_64
- JBoss Enterprise Application Platform 7.4 for RHEL 8 x86_64
- JBoss Enterprise Application Platform 7.4 for RHEL 7 x86_64
- JBoss Enterprise Application Platform Text-Only Advisories x86_64
Overview
A vulnerability has been reported in Red Hat JBoss which could be exploited by a remote attacker to perform Denial of Service (DoS) condition on the targeted system.
Description
This vulnerability exists in Red Hat JBoss due to unexpected handshake status updated in SslConduit, where the loop never terminates.
A remote attacker could exploit this vulnerability to consume all system resources and perform Denial of Service (DoS) condition on the targeted system.
Solution
Apply appropriate fix/patches as mentioned in the following link
https://access.redhat.com/errata/RHSA-2023:1184
https://access.redhat.com/errata/RHSA-2023:1185
Vendor Information
RedHat
https://access.redhat.com/errata/RHSA-2023:1184
https://access.redhat.com/errata/RHSA-2023:1185
References
RedHat
https://access.redhat.com/errata/RHSA-2023:1184
https://access.redhat.com/errata/RHSA-2023:1185
CVE Name
CVE-2023-1108
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|