redhat jboss-remoting CVE-2020-35510 is a vulnerability in Red Hat Jboss Remoting
Published on June 2, 2021

A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the lines that send the ACK message from the EJB client code resulting in a denial of service. The highest threat from this vulnerability is to system availability.

NVD

Weakness Type

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2020-35510 has been classified to as a Resource Exhaustion vulnerability or weakness.


Products Associated with CVE-2020-35510

Want to know whenever a new CVE is published for Red Hat Jboss Remoting? stack.watch will email you.

 

Exploit Probability

EPSS
0.56%
Percentile
68.00%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.