7.5
CWE
401
Advisory Published
CVE Published
Updated

CVE-2022-0853

First published: Fri Mar 04 2022(Updated: )

A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

Credit: secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
redhat/eap7-wildfly-http-client<0:1.1.11-1.SP1_redhat_00001.1.el8ea
0:1.1.11-1.SP1_redhat_00001.1.el8ea
redhat/eap7-wildfly-http-client<0:1.1.11-1.SP1_redhat_00001.1.el7ea
0:1.1.11-1.SP1_redhat_00001.1.el7ea
redhat/rh-sso7-keycloak<0:18.0.3-1.redhat_00001.1.el7
0:18.0.3-1.redhat_00001.1.el7
redhat/rh-sso7-keycloak<0:18.0.3-1.redhat_00001.1.el8
0:18.0.3-1.redhat_00001.1.el8
redhat/rh-sso7<0:1-5.el9
0:1-5.el9
redhat/rh-sso7-javapackages-tools<0:6.0.0-7.el9
0:6.0.0-7.el9
redhat/rh-sso7-keycloak<0:18.0.3-1.redhat_00001.1.el9
0:18.0.3-1.redhat_00001.1.el9
Redhat Descision Manager=7.0
Redhat Jboss Enterprise Application Platform=7.0.0
Redhat Jboss Enterprise Application Platform Expansion Pack
Redhat Process Automation=7.0
Redhat Single Sign-on=7.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-0853?

    CVE-2022-0853 is a vulnerability found in JBoss-client that leads to a memory leak and information leakage.

  • What is the severity of CVE-2022-0853?

    CVE-2022-0853 has a severity level of 7.5 (high).

  • Which software is affected by CVE-2022-0853?

    The following software is affected: eap7-wildfly-http-client (el8 and el7), rh-sso7-keycloak (el7, el8, and el9), rh-sso7, rh-sso7-javapackages-tools, Redhat Descision Manager, Redhat Jboss Enterprise Application Platform, Redhat Jboss Enterprise Application Platform Expansion Pack, and Redhat Process Automation.

  • How does CVE-2022-0853 occur?

    CVE-2022-0853 occurs due to a memory leak on the JBoss client-side when using UserTransaction repeatedly.

  • Are there any references for CVE-2022-0853?

    Yes, you can find references for CVE-2022-0853 at the following links: [link 1](https://access.redhat.com/errata/RHSA-2022:4922), [link 2](https://access.redhat.com/errata/RHSA-2022:4918), [link 3](https://access.redhat.com/errata/RHSA-2022:4919).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203