CVE-2020-25644: Netapp Oncommand Insight
High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Affected products
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Service Level Manager: affected versions not specified
- Red Hat Data Grid: version 8.0 only
- Red Hat JBoss Data Grid: version 7.0.0 only
- Red Hat JBoss Enterprise Application Platform: version 7.0.0 only
- Red Hat JBoss Fuse: version 7.0.0 only
- Red Hat Openshift Application Runtimes: affected versions not specified
- Red Hat Single Sign-On: version 7.0 only
- Red Hat Wildfly OpenSSL: before 1.1.3 (fixed in 1.1.3)
Published 2020-10-06. Last modified 2026-06-17.