First published: Thu Aug 11 2022(Updated: )
A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LAST_CHUNK from the bytes, causing a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-undertow | <0:2.2.20-1.SP1_redhat_00001.1.el8ea | 0:2.2.20-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.2.20-1.SP1_redhat_00001.1.el9ea | 0:2.2.20-1.SP1_redhat_00001.1.el9ea |
redhat/eap7-undertow | <0:2.2.20-1.SP1_redhat_00001.1.el7ea | 0:2.2.20-1.SP1_redhat_00001.1.el7ea |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el7 | 0:18.0.6-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el8 | 0:18.0.6-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.6-1.redhat_00001.1.el9 | 0:18.0.6-1.redhat_00001.1.el9 |
Redhat Integration Camel K | ||
Redhat Jboss Enterprise Application Platform | =7.0.0 | |
Redhat Jboss Fuse | =7.0.0 | |
Redhat Single Sign-on | =7.0 | |
Redhat Undertow | >=2.0.0<=2.2.19 | |
Redhat Undertow | =2.3.0-alpha1 | |
Redhat Undertow | =2.3.0-alpha2 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Cloud Secure Agent | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-2764 is a vulnerability found in Undertow with EJB invocations that allows an attacker to generate a valid HTTP request and send it to the server, causing a denial of service.
The affected software versions include eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el7ea, eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el8ea, eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el9ea, rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el7, rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el8, and rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el9.
CVE-2022-2764 has a severity level of medium.
The remedy for CVE-2022-2764 is to update eap7-undertow to version 2.2.20-1.SP1_redhat_00001.1.el7ea, 2.2.20-1.SP1_redhat_00001.1.el8ea, or 2.2.20-1.SP1_redhat_00001.1.el9ea, and update rh-sso7-keycloak to version 18.0.6-1.redhat_00001.1.el7, 18.0.6-1.redhat_00001.1.el8, or 18.0.6-1.redhat_00001.1.el9.
You can find more information about CVE-2022-2764 at the following references: [link1], [link2], and [link3].