Impact
The flaw is an integer overflow in jboss‑remoting’s message reader that can be triggered during the Upgrade handshake. An unauthenticated attacker reaching the management or remote ports can cause out‑of‑memory errors, degrading all requests and ultimately disabling the service.
Affected Systems
Red Hat JBoss Enterprise Application Platform 7, 8, and the Expansion Pack are affected. The vulnerability can be exercised on any of the exposed management and remote ports: 8080, 9990, or 4447. No specific patch level is mentioned, so all versions of these products are potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact when the server is overloaded. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, yet the nature of the denial of service and the remote, unauthenticated trigger make it a realistic risk for exposed deployments. The likely attack vector is a remote network service: an attacker can connect to one of the exposed ports, complete the Upgrade handshake, and send a crafted payload that overflows the message reader, causing the server to run out of memory. This attack does not require initial authentication and affects server availability across all applications running on the instance.
OpenCVE Enrichment