5.9
CVSSv3

CVE-2016-7046

Published: 03/10/2016 Updated: 15/12/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote malicious users to cause a denial of service (CPU and disk consumption) via a long URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 7.0

Vendor Advisories

Debian Bug report logs - #838600 undertow: CVE-2016-7046: Long URL proxy request lead to javanioBufferOverflowException and DoS Package: src:undertow; Maintainer for src:undertow is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu ...
Synopsis Important: jboss-ec2-eap package for EAP 703 Type/Severity Security Advisory: Important Topic The jboss-ec2-eap package that adds an enhancement is now available for Red Hat JBoss Enterprise Application Platform 703 on Red Hat Enterprise Linux 6 and 7Red Hat Product Security has rated this upd ...
Synopsis Important: JBoss Enterprise Application Platform 703 on RHEL 6 Type/Severity Security Advisory: Important Topic Updated packages that provide Red Hat JBoss Enterprise Application Platform 703 that fix several bugs and add various enhancements that are now available for Red Hat Enterprise Linux ...
Synopsis Important: JBoss Enterprise Application Platform 703 for RHEL 7 Type/Severity Security Advisory: Important Topic Updated packages that provides Red Hat JBoss Enterprise Application Platform 703, fixes several bugs, and adds various enhancements are now available for Red Hat Enterprise Linux 7R ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 710 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 710 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a ...
Synopsis Important: eap7-jboss-ec2-eap security update Type/Severity Security Advisory: Important Topic An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 71 for Red Hat Ent ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 710 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application PlatformRed Hat Product Security has rated this update as having a security impact of Important A Com ...
It was discovered that a long URL sent to EAP 7 Server operating as a reverse proxy with default buffer sizes causes a Denial of Service ...