A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetapp Cloud Secure Agent
APPNetappall versionsNetapp Oncommand Insight
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsRed Hat Jboss Enterprise Application Platform
APPRedhat7.37.4Red Hat Single Sign On
APPRedhat7.4.107.5.1Red Hat Undertow
APPRedhat< 2.2.15
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
References
Related vulnerabilities
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP