VDB

RHSA-2022%3A8793

RHSA-2022%3A8793 PUBLISHED CVSS 4.199999809265137 MEDIUM

A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LAST_CHUNK from the bytes, causing a denial of service.

Risk Scores

CVSS 3.1
4.199999809265137
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatNone.globals-9.18.0 as a component of Red Hat JBoss Enterprise Application Platform None.globals-9.18.0
Red Hatorg.jboss.eap.wildfly-weld-ejb-7.4.8.GA-redhat-00002.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red HatNone.pom.xml-None as a component of Red Hat JBoss Enterprise Application Platform None.pom.xml-None
Red Hatorg.jboss.ironjacamar.ironjacamar-common-impl-1.5.3.SP2-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform org.jboss.ironjacamar.ironjacamar-common-impl-1.5.3.SP2-redhat-00001.jar
Red Hatjakarta.enterprise.jakarta.enterprise.cdi-api-2.0.2.redhat-00002.jar as a component of Red Hat JBoss Enterprise Application Platform jakarta.enterprise.jakarta.enterprise.cdi-api-2.0.2.redhat-00002.jar
Red HatNone.chownr-1.1.1 as a component of Red Hat JBoss Enterprise Application Platform None.chownr-1.1.1
Red HatNone.union-value-1.0.1 as a component of Red Hat JBoss Enterprise Application Platform None.union-value-1.0.1
Red Hatio.agroal.agroal-narayana-1.3.0.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.apache.cxf.cxf-tools-common-3.3.13.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform org.apache.cxf.cxf-tools-common-3.3.13.redhat-00001.pom
Red Hatorg.jboss.weld.module.weld-jta-3.1.6.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform org.jboss.weld.module.weld-jta-3.1.6.Final-redhat-00001.jar
Red Hatorg.aesh.readline-2.2.0.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform org.aesh.readline-2.2.0.redhat-00001.pom
Red HatNone.extsprintf-1.3.0 as a component of Red Hat JBoss Enterprise Application Platform None.extsprintf-1.3.0
Red Hatorg.apache.httpcomponents.httpasyncclient-4.1.4.redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.glassfish.jaxb.jaxb-xjc-2.3.3.b02-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.infinispan.infinispan-hibernate-cache-spi-11.0.16.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform org.infinispan.infinispan-hibernate-cache-spi-11.0.16.Final-redhat-00001.jar
Red Hatorg.apache.cxf.cxf-rt-ws-policy-3.3.13.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.jctools.jctools-core-3.1.0.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.jboss.logmanager.jboss-logmanager-2.1.18.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform org.jboss.logmanager.jboss-logmanager-2.1.18.Final-redhat-00001.jar
Red Hatorg.apache.activemq.artemis-jms-server-2.16.0.redhat-00045.pom as a component of Red Hat JBoss Enterprise Application Platform org.apache.activemq.artemis-jms-server-2.16.0.redhat-00045.pom
Red Hatorg.infinispan.infinispan-cachestore-remote-11.0.16.Final-redhat-00001.jar as a component of Red Hat JBoss Enterprise Application Platform *

…and 2098 more

Timeline

  • Dec 5, 2022 CVE Published
  • Mar 27, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›