CVE-2023-1973: Red Hat JBoss Enterprise Application Platform 7

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Affected products

  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 8: before 0:2.2.30-1.SP1_redhat_00001.1.el8eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el8eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 9: before 0:2.2.30-1.SP1_redhat_00001.1.el9eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el9eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 On Rhel 7: before 0:2.2.30-1.SP1_redhat_00001.1.el7eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el7eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:2.3.11-1.SP1_redhat_00001.1.el8eap (fixed in 0:2.3.11-1.SP1_redhat_00001.1.el8eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:2.3.11-1.SP1_redhat_00001.1.el9eap (fixed in 0:2.3.11-1.SP1_redhat_00001.1.el9eap)

Published 2024-11-07. Last modified 2026-06-17.