Impact
A flaw in WildFly core allows an authenticated administrative user to inject an improperly formatted payload into the Inet Address field via the Management Model, resulting in a server crash that is unrecoverable. The injected payload is written into the standalone.xml configuration file, forcing manual intervention to restore operation and causing a denial of service.
Affected Systems
Affected vendors include Red Hat; products impacted are Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, and Red Hat Single Sign‑On 7. Specific version ranges are not listed in the advisory.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticating with administrative privileges to the WildFly management interface, likely through the web console or CLI. The attack vector is therefore an authenticated internal user or a compromised admin credential and leads to an unrecoverable denial of service.
OpenCVE Enrichment