CVE-2017-7561

HIGH7.5EPSS 1.1%

Inconsistent Interpretation of HTTP Requests in Red Hat JBoss EAP

Published: 5/13/2022Modified: 4/28/2026

Description

Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (12)