CVE-2022-1319
31.08.2022, 16:15
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | openshift_application_runtimes | - |
redhat | single_sign-on | 7.0 |
redhat | undertow | 𝑥 < 2.2.17 |
redhat | undertow | 2.2.17 |
redhat | undertow | 2.2.17:sp1 |
redhat | undertow | 2.2.17:sp2 |
redhat | undertow | 2.2.19 |
redhat | undertow | 2.2.19:sp1 |
redhat | undertow | 2.3.0:alpha1 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_secure_agent | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References