A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
2022-08-26T16:15:09.623
2024-11-21T06:22:40.440
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | jboss_enterprise_application_platform | 7.3 | Yes |
| Application | redhat | jboss_enterprise_application_platform | 7.4 | Yes |
| Application | redhat | single_sign-on | 7.4.10 | Yes |
| Application | redhat | single_sign-on | 7.5.1 | Yes |
| Application | redhat | undertow | < 2.2.15 | Yes |
| Application | netapp | cloud_secure_agent | - | Yes |
| Application | netapp | oncommand_insight | - | Yes |
| Application | netapp | oncommand_workflow_automation | - | Yes |