Impact
A flaw in Wildfly allows a remote unauthenticated attacker to cause an OutOfMemoryError by sending a specially crafted CSIv2Util GSS token that contains an unchecked length field. The decoder parses the length without bounds checking and attempts to allocate a byte array of that size, exhausting memory and resulting in a service crash. This denial of service can be triggered purely over the network and does not require any authentication.
Affected Systems
The vulnerability affects Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and Red Hat Single Sign-On 7. Affected versions are not specified beyond the product families listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is unavailable but the vulnerability can be exploited by an unauthenticated remote attacker, making it highly accessible. It is not listed in the CISA KEV catalog. The likely attack vector is over the network, directing traffic to the IIoP listener. An attacker can repeatedly trigger OOM conditions, disrupting availability of the application server.
OpenCVE Enrichment