CVE-2023-1973: Red Hat JBoss Enterprise Application Platform 7
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
Affected products
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 8: before 0:2.2.30-1.SP1_redhat_00001.1.el8eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 9: before 0:2.2.30-1.SP1_redhat_00001.1.el9eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el9eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 On Rhel 7: before 0:2.2.30-1.SP1_redhat_00001.1.el7eap (fixed in 0:2.2.30-1.SP1_redhat_00001.1.el7eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:2.3.11-1.SP1_redhat_00001.1.el8eap (fixed in 0:2.3.11-1.SP1_redhat_00001.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:2.3.11-1.SP1_redhat_00001.1.el9eap (fixed in 0:2.3.11-1.SP1_redhat_00001.1.el9eap)
Published 2024-11-07. Last modified 2026-06-17.