CVE-2019-19343
23.03.2021, 21:15
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss-remoting | 𝑥 < 5.0.14 |
redhat | jboss-remoting | 5.0.14 |
redhat | jboss_enterprise_application_platform | 𝑥 < 7.2.4 |
redhat | undertow | 𝑥 < 2.0.25 |
redhat | undertow | 2.0.25 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-404 - Improper Resource Shutdown or ReleaseThe program does not release or incorrectly releases a resource before it is made available for re-use.
References