CVE-2020-14340: Oracle Communications Cloud Native Core Console

Medium severity, CVSS 5.9. EPSS: 2.2% chance of exploitation in the next 30 days.

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.

Affected products

  • Oracle Communications Cloud Native Core Console: version 1.9.0 only
  • Oracle Communications Cloud Native Core Network Repository Function: version 1.14.0 only
  • Oracle Communications Cloud Native Core Policy: version 1.14.0 only
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy: version 1.15.0 only
  • Oracle Communications Cloud Native Core Service Communication Proxy: version 1.14.0 only
  • Oracle Communications Cloud Native Core Unified Data Repository: version 1.14.0 only
  • Red Hat JBoss Brms: version 5 only; version 6 only
  • Red Hat JBoss Data Grid: version 6.0.0 only; version 7.0.0 only
  • Red Hat JBoss Data Virtualization: version 6.0.0 only
  • Red Hat JBoss Enterprise Application Platform: version 5.0.0 only; version 6.0.0 only
  • Red Hat JBoss Fuse: version 6.0.0 only; version 7.0.0 only
  • Red Hat JBoss Operations Network: version 3.0 only
  • Red Hat JBoss Soa Platform: version 5 only
  • Red Hat Xnio: from 3.6.1, before 3.7.9 (fixed in 3.7.9); from 3.8.0, before 3.8.2 (fixed in 3.8.2); version 3.6.0 only

Published 2021-06-02. Last modified 2026-06-17.