CVE-2015-5220: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 5.0. EPSS: 3% chance of exploitation in the next 30 days.

The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.

Affected products

  • Red Hat JBoss Enterprise Application Platform: up to and including 6.4.3
  • Red Hat JBoss Wildfly Application Server: up to and including 2.0.0

Published 2015-10-27. Last modified 2026-06-17.