VDB
RHSA-2022%3A8793
RHSA-2022%3A8793
PUBLISHED
CVSS 4.199999809265137 MEDIUM
A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LAST_CHUNK from the bytes, causing a denial of service.
Risk Scores
CVSS 3.1
4.199999809265137
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | None.globals-9.18.0 as a component of Red Hat JBoss Enterprise Application Platform | None.globals-9.18.0 |
| Red Hat | org.jboss.eap.wildfly-weld-ejb-7.4.8.GA-redhat-00002.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | None.pom.xml-None as a component of Red Hat JBoss Enterprise Application Platform | None.pom.xml-None |
| Red Hat | org.jboss.ironjacamar.ironjacamar-common-impl-1.5.3.SP2-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.ironjacamar.ironjacamar-common-impl-1.5.3.SP2-redhat-00001.jar |
| Red Hat | jakarta.enterprise.jakarta.enterprise.cdi-api-2.0.2.redhat-00002.jar as a component of Red Hat JBoss Enterprise Application Platform | jakarta.enterprise.jakarta.enterprise.cdi-api-2.0.2.redhat-00002.jar |
| Red Hat | None.chownr-1.1.1 as a component of Red Hat JBoss Enterprise Application Platform | None.chownr-1.1.1 |
| Red Hat | None.union-value-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.union-value-1.0.1 |
| Red Hat | io.agroal.agroal-narayana-1.3.0.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.apache.cxf.cxf-tools-common-3.3.13.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | org.apache.cxf.cxf-tools-common-3.3.13.redhat-00001.pom |
| Red Hat | org.jboss.weld.module.weld-jta-3.1.6.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.weld.module.weld-jta-3.1.6.Final-redhat-00001.jar |
| Red Hat | org.aesh.readline-2.2.0.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | org.aesh.readline-2.2.0.redhat-00001.pom |
| Red Hat | None.extsprintf-1.3.0 as a component of Red Hat JBoss Enterprise Application Platform | None.extsprintf-1.3.0 |
| Red Hat | org.apache.httpcomponents.httpasyncclient-4.1.4.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.glassfish.jaxb.jaxb-xjc-2.3.3.b02-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.infinispan.infinispan-hibernate-cache-spi-11.0.16.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.infinispan.infinispan-hibernate-cache-spi-11.0.16.Final-redhat-00001.jar |
| Red Hat | org.apache.cxf.cxf-rt-ws-policy-3.3.13.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.jctools.jctools-core-3.1.0.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.jboss.logmanager.jboss-logmanager-2.1.18.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.logmanager.jboss-logmanager-2.1.18.Final-redhat-00001.jar |
| Red Hat | org.apache.activemq.artemis-jms-server-2.16.0.redhat-00045.pom as a component of Red Hat JBoss Enterprise Application Platform | org.apache.activemq.artemis-jms-server-2.16.0.redhat-00045.pom |
| Red Hat | org.infinispan.infinispan-cachestore-remote-11.0.16.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
…and 2098 more
Timeline
- Dec 5, 2022 CVE Published
- Mar 27, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:8793 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2117506 issue
- https://issues.redhat.com/browse/JBEAP-23913 advisory
- https://issues.redhat.com/browse/JBEAP-23997 advisory
- https://issues.redhat.com/browse/JBEAP-23998 advisory
- https://issues.redhat.com/browse/JBEAP-24011 advisory
- https://issues.redhat.com/browse/JBEAP-24013 advisory
- https://issues.redhat.com/browse/JBEAP-24028 advisory
- https://issues.redhat.com/browse/JBEAP-24030 advisory
- https://issues.redhat.com/browse/JBEAP-24031 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_8793.json advisory
- https://access.redhat.com/security/cve/CVE-2022-2764 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2764 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2764 advisory