CVE-2022-0853 is a memory leak vulnerability in the JBoss client, specifically when UserTransaction is repeatedly used. This flaw affects Red Hat products including Decision Manager, JBoss Enterprise Application Platform, JBoss Enterprise Application Platform Expansion Pack, Process Automation, and Single Sign-On. With a CVSS score of 7.5 (HIGH), it is a network-exploitable vulnerability that can lead to a denial of service (availability impact) without requiring user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:descision_manager:7.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.