Impact
A crafted UDP multicast datagram can trigger a NullPointerException in the mod_cluster AdvertiseListenerImpl, causing the advertise listener thread to terminate permanently. The listener continues to report itself as active but is functionally dead, resulting in the affected application server failing to advertise to the load balancer until the node is restarted. This causes a denial of service scenario for services relying on mod_cluster discovery, without granting attacker code execution or access to the underlying system.
Affected Systems
The flaw affects Red Hat JBoss Enterprise Application Platform versions 7, 8, and the Expansion Pack, Red Hat JBoss Web Server versions 5, 6, 7, and Red Hat Single Sign-On 7. All released releases of these products are potentially impacted; specific version details were not enumerated in the advisory.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score of 0.00841 indicates a very low but non‑zero exploitation probability, the vulnerability is a moderate severity issue. The attack vector is remote via UDP multicast on 224.0.1.105:23364; any host that can send packets to this address can trigger the denial of service. The vulnerability is not listed in the CISA KEV catalog, and no code execution or privilege escalation is possible. The recommended approach is to mitigate via configuration changes rather than relying on a patch at this time.
OpenCVE Enrichment