Denial of Service Vulnerability in JBoss Remoting by Red Hat
CVE-2026-15562

7.5HIGH

What is CVE-2026-15562?

A vulnerability exists in JBoss Remoting that allows a remote attacker to exploit it through the Upgrade handshake process on specific ports (8080, 9990, or 4447). Successful exploitation can lead to out-of-memory (OOM) errors that affect the server's ability to handle requests, ultimately resulting in a denial of service for legitimate users. It is crucial for system administrators to apply security patches and assess their configurations to prevent unauthorized access.

Affected Version(s)

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.