The vendor explicitly identifies these products as affected by this CVE.
- wildfly-iiop-openjdk as a component of Red Hat Fuse 7
- wildfly-iiop-openjdk as a component of Red Hat JBoss Enterprise Application Platform 7
- wildfly-iiop-openjdk as a component of Red Hat JBoss Enterprise Application Platform 8
- wildfly-iiop-openjdk as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
- Remediation
- Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
