HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-3859

CVSS 7.5v3.1pub. 2022-08-26upd. 2024-11-21

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Netapp Cloud Secure Agent

    APP
    Netapp
    all versions
  • Netapp Oncommand Insight

    APP
    Netapp
    all versions
  • Netapp Oncommand Workflow Automation

    APP
    Netapp
    all versions
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.37.4
  • Red Hat Single Sign On

    APP
    Redhat
    7.4.107.5.1
  • Red Hat Undertow

    APP
    Redhat
    < 2.2.15
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product

RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)

CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP