4.9

CVE-2022-2764

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Integration Camel K Version -
Redhat ≫ Jboss Fuse Version 7.0.0
Redhat ≫ Single Sign-on Version 7.0
Redhat ≫ Undertow Version >= 2.0.0 <= 2.2.19
Redhat ≫ Undertow Version 2.3.0 Update alpha1
Redhat ≫ Undertow Version 2.3.0 Update alpha2
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Cloud Secure Agent Version -
Netapp ≫ Oncommand Insight Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.535
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://security.netapp.com/advisory/ntap-20221014-0006/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2117506
Vendor Advisory
Issue Tracking