Impact
Repeated HTTP requests to the RHCS TLS endpoint can trigger an Out of Memory condition, causing the Java process to crash and the service to become unavailable. The flaw is a memory‑leak vulnerability (CWE‑772) that can be exploited by any unauthenticated user without needing privileged access.
Affected Systems
Red Hat Certificate System 9 and Red Hat Enterprise Linux releases 8, 9, and 10 are affected.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. EPSS of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Repeated attempts can force a restart of the RHCS process, potentially requiring manual intervention.
OpenCVE Enrichment