A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
2020-01-23T17:15:11.767
2024-11-21T04:27:36.977
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | undertow | ≤ 2.0.28 | Yes |
Application | redhat | jboss_data_grid | - | Yes |
Application | redhat | jboss_data_grid | 7.0.0 | Yes |
Application | redhat | jboss_enterprise_application_platform | 7.0.0 | Yes |
Application | redhat | jboss_fuse | 6.0.0 | Yes |
Application | redhat | jboss_fuse | 7.0.0 | Yes |
Application | redhat | single_sign-on | 7.0 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |