CVE-2021-3859
26.08.2022, 16:15
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 7.3 |
redhat | jboss_enterprise_application_platform | 7.4 |
redhat | single_sign-on | 7.4.10 |
redhat | single_sign-on | 7.5.1 |
redhat | undertow | 𝑥 < 2.2.15 |
netapp | cloud_secure_agent | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-214 - Invocation of Process Using Visible Sensitive InformationA process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References