A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14888 | issue tracking vendor advisory |
https://access.redhat.com/errata/RHSA-2020:0729 | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20220211-0001/ | third party advisory |