CVE-2015-5220: Buffer Overflow
no sanity checks and unbounded header sizes/counts leads to OOME from EAP 6 http management console
Other sources
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5220?
The severity of CVE-2015-5220 is classified as a denial of service vulnerability with potential high impact due to memory consumption.
How do I fix CVE-2015-5220?
To fix CVE-2015-5220, upgrade to Red Hat JBoss Enterprise Application Platform version 6.4.4 or later, or update to the latest version of WildFly.
What systems are affected by CVE-2015-5220?
CVE-2015-5220 affects Red Hat JBoss Enterprise Application Platform versions prior to 6.4.4 and WildFly versions up to 2.0.0.
What type of attack does CVE-2015-5220 enable?
CVE-2015-5220 enables remote attackers to exploit memory consumption vulnerabilities leading to denial of service.
When was CVE-2015-5220 reported?
CVE-2015-5220 was reported as a vulnerability in April 2015.