CVE-2020-14297: Red Hat Amq
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
Affected products
- Red Hat Amq: version 2.0 only
- Red Hat JBoss-Ejb-Client: from 1.0.0, before 4.0.34 (fixed in 4.0.34)
- Red Hat JBoss Enterprise Application Platform Continuous Delivery: affected versions not specified
- Red Hat JBoss Fuse: version 6.0.0 only
- Red Hat Openshift Application Runtimes: affected versions not specified
- Red Hat Single Sign-On: version 7.0 only
Published 2020-07-24. Last modified 2026-06-17.