CVE-2015-5220

Impact:
Important
Public Date:
2015-10-15
CWE:
CWE-770
Bugzilla:
1255597: CVE-2015-5220 OOME from EAP 6 http management console
It was discovered that sending requests containing large headers to the Web Console produced a Java OutOfMemoryError in the HTTP management interface. An attacker could use this flaw to cause a denial of service.

Find out more about CVE-2015-5220 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 7.8
Base Metrics AV:N/AC:L/Au:N/C:N/I:N/A:C
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server (httpserver) RHSA-2015:1906 2015-10-15
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jboss-ec2-eap) RHSA-2015:1907 2015-10-15
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (httpserver) RHSA-2015:1905 2015-10-15
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server (httpserver) RHSA-2015:1904 2015-10-15
Red Hat JBoss Operations Network 3.3 RHSA-2016:1519 2016-07-27

Affected Packages State

Platform Package State
Red Hat JBoss EAP 6 other Affected

Acknowledgements

This issue was discovered by Aaron Ogburn of Red Hat GSS Middleware Team

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.