5.9

CVE-2021-3629

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Integration Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version - SwEdition text-only
Redhat ≫ Single Sign-on Version - SwEdition text-only
Redhat ≫ Undertow Version < 2.0.40
Redhat ≫ Undertow Version >= 2.2.0 < 2.2.11
Redhat ≫ Wildfly Core Version < 17.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
   Redhat ≫ Enterprise Linux Version 6.0
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://bugzilla.redhat.com/show_bug.cgi?id=1977362
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20220729-0008/
Third Party Advisory