CVE-2016-7046: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 5.9. EPSS: 2.5% chance of exploitation in the next 30 days.

Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.0 only

Published 2016-10-03. Last modified 2026-06-17.