CVE-2020-25644: Netapp Oncommand Insight

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

Affected products

  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Red Hat Data Grid: version 8.0 only
  • Red Hat JBoss Data Grid: version 7.0.0 only
  • Red Hat JBoss Enterprise Application Platform: version 7.0.0 only
  • Red Hat JBoss Fuse: version 7.0.0 only
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Single Sign-On: version 7.0 only
  • Red Hat Wildfly OpenSSL: before 1.1.3 (fixed in 1.1.3)

Published 2020-10-06. Last modified 2026-06-17.